CVE-2019-0304

FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
sapCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
sapadvanced_business_application_programming_platform_kernel
7.21
sapadvanced_business_application_programming_platform_kernel
7.45
sapadvanced_business_application_programming_platform_kernel
7.49
sapadvanced_business_application_programming_platform_kernel
7.53
sapadvanced_business_application_programming_platform_kernel
7.73
sapadvanced_business_application_programming_platform_krnl32nuc
7.21
sapadvanced_business_application_programming_platform_krnl32nuc
7.21ext:ext
sapadvanced_business_application_programming_platform_krnl32nuc
7.22
sapadvanced_business_application_programming_platform_krnl32nuc
7.22ext:ext
sapadvanced_business_application_programming_platform_krnl32uc
7.21
sapadvanced_business_application_programming_platform_krnl32uc
7.21ext:ext
sapadvanced_business_application_programming_platform_krnl32uc
7.22
sapadvanced_business_application_programming_platform_krnl32uc
7.22ext:ext
sapadvanced_business_application_programming_platform_krnl64nuc
7.21
sapadvanced_business_application_programming_platform_krnl64nuc
7.21ext:ext
sapadvanced_business_application_programming_platform_krnl64nuc
7.22
sapadvanced_business_application_programming_platform_krnl64nuc
7.22ext:ext
sapadvanced_business_application_programming_platform_krnl64nuc
7.49
sapadvanced_business_application_programming_platform_krnl64uc
7.21
sapadvanced_business_application_programming_platform_krnl64uc
7.21ext:ext
sapadvanced_business_application_programming_platform_krnl64uc
7.22
sapadvanced_business_application_programming_platform_krnl64uc
7.22ext:ext
sapadvanced_business_application_programming_platform_krnl64uc
7.49
sapadvanced_business_application_programming_platform_krnl64uc
7.73
𝑥
= Vulnerable software versions