Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0328


ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system.


Published

2019-07-10T20:15:12.123

Last Modified

2024-11-21T04:16:41.410

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_process_integration 7.0 Yes
Application sap netweaver_process_integration 7.1 Yes
Application sap netweaver_process_integration 7.3 Yes
Application sap netweaver_process_integration 7.4 Yes
Application sap netweaver_process_integration 7.5 Yes
Application sap netweaver_process_integration 7.31 Yes

References