CVE-2019-0330: Code Injection
The OS Command Plugin in the transaction GPAADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0330?
CVE-2019-0330 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2019-0330?
To fix CVE-2019-0330, update the SAP Diagnostics Agent to the latest version that addresses this vulnerability.
What applications are affected by CVE-2019-0330?
CVE-2019-0330 affects the SAP Diagnostic Agent version 7.20.
What type of vulnerability is CVE-2019-0330?
CVE-2019-0330 is an OS command injection vulnerability that allows for code execution.
Can CVE-2019-0330 lead to data breaches?
Yes, CVE-2019-0330 can potentially lead to data breaches if exploited, as attackers can control the application's behavior.