cbcvebase.
CVE-2019-0328
published 2019-07-10

CVE-2019-0328: ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands…

PriorityP346high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
3.42%
87.5th percentile
ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system.

Affected

12 ranges
VendorProductVersion rangeFixed in
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sap_sesap_netweaver_process_integration_abap_tests< 7.07.0
sap_sesap_netweaver_process_integration_abap_tests< 7.17.1
sap_sesap_netweaver_process_integration_abap_tests< 7.37.3
sap_sesap_netweaver_process_integration_abap_tests< 7.317.31
sap_sesap_netweaver_process_integration_abap_tests< 7.47.4
sap_sesap_netweaver_process_integration_abap_tests< 7.57.5

CVSS provenance

nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.