Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0351


A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Because of this, an attacker can exploit Services Registry potentially enabling them to take complete control of the product, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.


Published

2019-08-14T14:15:16.807

Last Modified

2024-11-21T04:16:43.777

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver 7.10 Yes
Application sap netweaver 7.20 Yes
Application sap netweaver 7.30 Yes
Application sap netweaver 7.31 Yes
Application sap netweaver 7.40 Yes
Application sap netweaver 7.50 Yes

References