SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML signatures and send arbitrary requests to the server via PI Axis adapter. These requests will be accepted by the PI Axis adapter even if the payload has been altered, especially when the signed element is the body of the xml document.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: sap

Published: 2019-04-10T20:23:32

Updated: 2019-04-10T20:23:32

Reserved: 2018-11-26T00:00:00


Link: CVE-2019-0283

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-04-10T21:29:01.277

Modified: 2020-08-24T17:37:01.140


Link: CVE-2019-0283

JSON object: View

cve-icon Redhat Information

No data.

CWE