First published: Wed Jun 12 2019(Updated: )
FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Business Application Software | =7.21 | |
SAP Business Application Software | =7.45 | |
SAP Business Application Software | =7.49 | |
SAP Business Application Software | =7.53 | |
SAP Business Application Software | =7.73 | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.49 | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.49 | |
SAP Advanced Business Application Programming Platform | =7.73 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0304 is critical with a CVSS score of 9.8.
To fix the FTP Function vulnerability, apply the necessary patches provided by SAP according to SAP Note 2719530.
CVE-2019-0304 is associated with CWE-74.