Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2019-08-14T13:53:21

Updated: 2024-08-04T17:44:16.517Z

Reserved: 2018-11-26T00:00:00

Link: CVE-2019-0344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-14T14:15:16.463

Modified: 2020-08-24T17:37:01.140

Link: CVE-2019-0344

cve-icon Redhat

No data.