CVE-2019-0328
Summary
| CVE | CVE-2019-0328 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-10 20:15:00 UTC |
| Updated | 2019-07-18 13:37:00 UTC |
| Description | ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Process Integration | 7.0 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.1 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.3 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.31 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.4 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.5 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.0 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.1 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.3 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.31 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.4 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP NetWeaver Process Integration CVE-2019-0328 Code Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| SAP Security Patch Day – July 2019 - Product Security Response at SAP - Community Wiki | CONFIRM | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.