CVE-2019-0343: Code Injection
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-0343?
CVE-2019-0343 is a vulnerability in SAP Commerce Cloud (Mediaconversion Extension) versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, and 1905 that allows an authenticated user to inject code and execute it in the application, leading to Code Injection.
What is the severity of CVE-2019-0343?
CVE-2019-0343 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2019-0343?
An attacker can exploit CVE-2019-0343 by injecting malicious code through the Backoffice/HMC user interface, giving them control over the application's behavior.
Which versions of SAP Commerce Cloud are affected by CVE-2019-0343?
CVE-2019-0343 affects SAP Commerce Cloud versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, and 1905.
How can I mitigate the risk of CVE-2019-0343?
To mitigate the risk of CVE-2019-0343, it is recommended to apply the necessary patches and updates provided by SAP as soon as they are available.