CVE-2019-0355Code Injection in SE SAP Netweaver AS FOR Java Engineapi

CWE-94Code Injection3 documents3 sources
Severity
7.2HIGHNVD
EPSS
0.4%
top 36.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateMay 24

Description

SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-jg8f-g534-227p: SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 72022-05-24
CVEList
CVE-2019-0355: SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 72019-09-10
CVE-2019-0355 — Code Injection | cvebase