cbcvebase.
CVE-2019-0351
published 2019-08-14

CVE-2019-0351: A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Because of…

PriorityP357high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.51%
82.9th percentile
A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Because of this, an attacker can exploit Services Registry potentially enabling them to take complete control of the product, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.

Affected

12 ranges
VendorProductVersion rangeFixed in
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sap_sesap_netweaver_uddi_server< 7.107.10
sap_sesap_netweaver_uddi_server< 7.207.20
sap_sesap_netweaver_uddi_server< 7.307.30
sap_sesap_netweaver_uddi_server< 7.317.31
sap_sesap_netweaver_uddi_server< 7.407.40
sap_sesap_netweaver_uddi_server< 7.507.50

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.