cbcvebase.
CVE-2019-0344
published 2019-08-14

CVE-2019-0344: Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute…

PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-21
Exploited in the wild
EPSS
7.08%
93.5th percentile
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.

Affected

14 ranges
VendorProductVersion rangeFixed in
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sap_sesap_commerce_cloud< 6.46.4
sap_sesap_commerce_cloud< 6.56.5
sap_sesap_commerce_cloud< 6.66.6
sap_sesap_commerce_cloud< 6.76.7
sap_sesap_commerce_cloud< 18081808
sap_sesap_commerce_cloud< 18111811
sap_sesap_commerce_cloud< 19051905

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability exists in the 'virtualjdbc' extension of SAP Commerce Cloud — monitor for exploitation attempts targeting this extension endpoint
  • The 'mediaconversion' extension is also an attack surface for this deserialization vulnerability — monitor deserialization activity in both mediaconversion and virtualjdbc extensions
  • Successful exploitation results in code execution under the 'Hybris' OS user — alert on unexpected process spawning or command execution by the 'Hybris' user account
  • ·Affected versions are explicitly scoped — ensure detection and patching efforts cover all listed versions: 6.4, 6.5, 6.6, 6.7, 1808, 1811, and 1905
  • ·Vendor advisory is archived — reference the Wayback Machine snapshot for patch guidance as the original SAP SCN wiki page may be unavailable

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.