Skip to content
COOEY

EXPOSURES › CVE-2019-0344

CVE-2019-0344

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-0344 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatchedransomware

SAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection.

SAP Commerce Cloud contained a deserialization vulnerability (CVE-2019-0344) enabling code injection through untrusted data, which was actively exploited before patching. DIB orgs must ensure SAP Commerce Cloud is patched and monitored for exploitation to prevent unauthorized access and compliance violations.

Shame score — Active exploitation of a known vulnerability in a widely used enterprise platform indicates a failure to maintain security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized