CVE-2019-0344

Publication date

2019-08-14 13:53:21

Family

sap

State

PUBLISHED

Description

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with Hybris user rights, resulting in Code Injection.