CVE-2019-0328

HIGH

SAP NetWeaver Process Integration - OS Command Injection

Title source: llm
STIX 2.1

Description

ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109067
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2774489

Scores

CVSS v3 7.2
EPSS 0.0085
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (6)
sap/netweaver_process_integration 7.0
sap/netweaver_process_integration 7.1
sap/netweaver_process_integration 7.3
sap/netweaver_process_integration 7.4
sap/netweaver_process_integration 7.5
sap/netweaver_process_integration 7.31
Published Jul 10, 2019
Tracked Since Feb 18, 2026