CVE-2019-0327

HIGH

SAP NetWeaver Application Server Java 7.1-7.5 - Unrestricted Upload of File with Dangerous Type

Title source: llm
STIX 2.1

Description

SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109071
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2777910

Scores

CVSS v3 7.2
EPSS 0.0210
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (6)
sap/netweaver_application_server_java 7.10
sap/netweaver_application_server_java 7.20
sap/netweaver_application_server_java 7.30
sap/netweaver_application_server_java 7.31
sap/netweaver_application_server_java 7.40
sap/netweaver_application_server_java 7.50
Published Jul 10, 2019
Tracked Since Feb 18, 2026