SAP Netweaver CVE-2019-0304 Remote Code Injection Vulnerability
BID:108701
Info
SAP Netweaver CVE-2019-0304 Remote Code Injection Vulnerability
| Bugtraq ID: | 108701 |
| Class: | Design Error |
| CVE: |
CVE-2019-0304 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2019 12:00AM |
| Updated: | Jun 11 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP NetWeaver ABAP KRNL64UC 7.21 SAP NetWeaver ABAP KRNL64NUC 7.21 SAP NetWeaver ABAP KRNL32UC 7.21 SAP NetWeaver ABAP KRNL32NUC 7.21 SAP NetWeaver ABAP 7.73 SAP NetWeaver ABAP 7.53 SAP NetWeaver ABAP 7.49 SAP NetWeaver ABAP 7.45 SAP NetWeaver ABAP 7.22EXT SAP NetWeaver ABAP 7.22 SAP NetWeaver ABAP 7.21EXT |
| Not Vulnerable: | |
Discussion
SAP Netweaver CVE-2019-0304 Remote Code Injection Vulnerability
SAP Netweaver is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
SAP Netweaver is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
Exploit / POC
SAP Netweaver CVE-2019-0304 Remote Code Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP Netweaver CVE-2019-0304 Remote Code Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP Netweaver CVE-2019-0304 Remote Code Injection Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Patch Day �?? June 2019 (SAP)
- Security Note #2719530 (SAP)