CVE-2019-0344: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
Other sources
SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Inventory SAP Commerce (Hybris) installations and determine whether any are running versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, or 1905; specifically check for the presence of the mediaconversion and virtualjdbc extensions, which contain deserialization of untrusted data vulnerabilities.
- Operational
If vendor-provided mitigations are unavailable for affected instances, discontinue use of the product (do not operate the impacted SAP Commerce installation) until a mitigation or fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0344?
The severity of CVE-2019-0344 is critical with a score of 9.8.
Which versions of SAP Commerce Cloud are affected by CVE-2019-0344?
SAP Commerce Cloud versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, and 1905 are affected by CVE-2019-0344.
What is the impact of CVE-2019-0344?
CVE-2019-0344 allows attackers to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
How can I fix CVE-2019-0344?
To fix CVE-2019-0344, it is recommended to apply the necessary patches provided by SAP or update to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-0344?
More information about CVE-2019-0344 can be found at the following references: [link1], [link2].