cbcvebase.
CVE-2019-0327
published 2019-07-10

CVE-2019-0327: SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4…

high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.

Affected

12 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sap_sesap_netweaver_for_java_application_server_web_container< 7.17.1
sap_sesap_netweaver_for_java_application_server_web_container< 7.27.2
sap_sesap_netweaver_for_java_application_server_web_container< 7.37.3
sap_sesap_netweaver_for_java_application_server_web_container< 7.317.31
sap_sesap_netweaver_for_java_application_server_web_container< 7.47.4
sap_sesap_netweaver_for_java_application_server_web_container< 7.57.5