Back to search
CVE-2019-0344
Published: Aug 14, 2019
Modified: Oct 21, 2025
PUBLISHED
Description
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP Commerce Cloud (virtualjdbc extension) | affected < 6.4affected < 6.5affected < 6.6affected < 6.7affected < 1808+2 more versions |
References
https://launchpad.support.sap.com/#/notes/2786035
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now