Vulnerability Details CVE-2019-0267
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2019-0267
-
cpe:2.3:a:sap:manufacturing_integration_and_intelligence:15.0
-
cpe:2.3:a:sap:manufacturing_integration_and_intelligence:15.1
-
cpe:2.3:a:sap:manufacturing_integration_and_intelligence:15.2