Junglewise Threat Intelligence

CVE-2019-0344: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

CVE-2019-0344 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-30

Technologies: SAP Commerce Cloud. Vendors: SAP SE, SAP.

Executive brief

SAP Commerce Cloud (formerly Hybris) contains a deserialization of untrusted data vulnerability in the virtualjdbc and mediaconversion extensions. An unauthenticated attacker can exploit this to execute arbitrary code with 'Hybris' user rights.

Affected products

  • SAP SE Commerce Cloud 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905

Timeline

  • 2019-08-14: disclosed: NVD Published Date
  • 2024-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-30: exploited: Reported as exploited in the wild by CISA

Related threats