CVE-2019-0355: Code Injection
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-0355.
What is the severity of CVE-2019-0355?
The severity of CVE-2019-0355 is high with a CVSS score of 7.2.
Which versions of SAP NetWeaver Application Server Java Web Container are affected?
Versions 7.10, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver Application Server Java Web Container are affected.
What is the impact of this vulnerability?
This vulnerability allows an attacker to inject code that can be executed by the application, giving them control over the behavior of the application.
How can I fix CVE-2019-0355?
To fix CVE-2019-0355, apply the necessary patches or updates provided by SAP and follow their recommended security guidelines.