Executive brief
SAP Commerce Cloud (formerly Hybris) contains a deserialization of untrusted data vulnerability in the virtualjdbc and mediaconversion extensions. An unauthenticated attacker can exploit this to execute arbitrary code with 'Hybris' user rights.
Affected products
- SAP SE Commerce Cloud 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905
Timeline
- 2019-08-14: disclosed: NVD Published Date
- 2024-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-30: exploited: Reported as exploited in the wild by CISA