CVE-2019-0344
CRITICAL(9.8)KEV
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
Description
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| sap | commerce cloud | 6.4; 6.5; 6.6; 6.7; 1808; 1811; 1905 |
Multiple CVSS Assessments
Source: [email protected](Primary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- https://launchpad.support.sap.com/#/notes/2786035(Permissions Required, Vendor Advisory)
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017(Broken Link)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0344(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.