EXPOSURES › CVE-2019-0344
CVE-2019-0344
HIGH ⌖ ON CISA KEV · EXPLOITEDSAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection.
SAP Commerce Cloud contained a deserialization vulnerability (CVE-2019-0344) enabling code injection through untrusted data, which was actively exploited before patching. DIB orgs must ensure SAP Commerce Cloud is patched and monitored for exploitation to prevent unauthorized access and compliance violations.
Shame score — Active exploitation of a known vulnerability in a widely used enterprise platform indicates a failure to maintain security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |