CVE-2019-0344
14.08.2019, 14:15
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.Enginsight
Vendor | Product | Version |
---|---|---|
sap | commerce_cloud | 6.4 |
sap | commerce_cloud | 6.5 |
sap | commerce_cloud | 6.6 |
sap | commerce_cloud | 6.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration