CVE-2019-0344
published 2019-08-14CVE-2019-0344: Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute…
PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-21
Exploited in the wild
EPSS
7.08%
93.5th percentile
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | commerce_cloud | — | — |
| sap | commerce_cloud | — | — |
| sap | commerce_cloud | — | — |
| sap | commerce_cloud | — | — |
| sap | commerce_cloud | — | — |
| sap | commerce_cloud | — | — |
| sap | commerce_cloud | — | — |
| sap_se | sap_commerce_cloud | < 6.4 | 6.4 |
| sap_se | sap_commerce_cloud | < 6.5 | 6.5 |
| sap_se | sap_commerce_cloud | < 6.6 | 6.6 |
| sap_se | sap_commerce_cloud | < 6.7 | 6.7 |
| sap_se | sap_commerce_cloud | < 1808 | 1808 |
| sap_se | sap_commerce_cloud | < 1811 | 1811 |
| sap_se | sap_commerce_cloud | < 1905 | 1905 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability exists in the 'virtualjdbc' extension of SAP Commerce Cloud — monitor for exploitation attempts targeting this extension endpoint ↗
- →The 'mediaconversion' extension is also an attack surface for this deserialization vulnerability — monitor deserialization activity in both mediaconversion and virtualjdbc extensions ↗
- →Successful exploitation results in code execution under the 'Hybris' OS user — alert on unexpected process spawning or command execution by the 'Hybris' user account ↗
- ·Affected versions are explicitly scoped — ensure detection and patching efforts cover all listed versions: 6.4, 6.5, 6.6, 6.7, 1808, 1811, and 1905 ↗
- ·Vendor advisory is archived — reference the Wayback Machine snapshot for patch guidance as the original SAP SCN wiki page may be unavailable ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
cisa·2024-09-30·CVSS 9.8
CVE-2019-0344 [CRITICAL] CWE-502 SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
Vulnerability: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
Affected: SAP Commerce Cloud
SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://web.archive.org/web/20191214053020/https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 ; https://nvd.nist.gov/vuln/detail/CVE-2019-0344
Remediation Due Date: 2024-10-21
GHSA
GHSA-75jg-chc9-wv8p: Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6
ghsa_unreviewed·2022-05-24
CVE-2019-0344 [CRITICAL] CWE-502 GHSA-75jg-chc9-wv8p: Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
VulnCheck
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
vulncheck·2019·CVSS 9.8
CVE-2019-0344 [CRITICAL] CWE-502 SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.
Affected: SAP Commerce Cloud
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2024-10-21
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://launchpad.support.sap.com/#/notes/2786035https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017https://launchpad.support.sap.com/#/notes/2786035https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0344
2019-08-14
Published
2024-09-30
Added to CISA KEV
Exploited in the wild