SAP security note 2773493, "[CVE-2019-0308] Code Injection vulnerability in SAP E-Commerce (Business-to-Consumer) Application", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP E-Commerce (Business-to-Consumer) application allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Some well-known impacts of Code Injection vulnerability are:
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
This note contains Java Correction(s) for E-Commerce / Web Channel. Implement the SP Patch Level attached to this note. For further information about installing Java Patches consult note 877887. Information about the patch strategy can be found in note 1546959.
Reason and prerequisites
Insufficient input validation.
CVSS
Score 6.8 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
References
Affected components
- SAP-CRMJAV: 730, 731, 732, 733, 754
- SAP-CRMWEB: 730, 731, 732, 733, 754
- SAP-SHRWEB: 730, 731, 732, 733, 754
- SAP-SHRJAV: 730, 731, 732, 733, 754
- SAP-CRMAPP: 730, 731, 732, 733, 754
- SAP-SHRAPP: 730, 731, 732, 733, 754
Full note on SAP: SAP Support Launchpad note 2773493
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
