SAP Security Note
HotNews
SAP security note 2800779, "[CVE-2019-0351] Remote Code Execution(RCE) in SAP NetWeaver UDDI Server (Services Registry)", is a program error note released on August 13, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Remote Code Execution vulnerability exists in the Services Registry. An attacker can exploit this vulnerability to take complete control of the product, including viewing, changing, or deleting data by injecting code into the working memory, which is subsequently executed by the application. It can also cause the product to terminate unexpectedly.
Solution
Please apply the provided patch.
CVSS
Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References
- 2830819 – FAQ about SAP Note 2800779
- 2842655 – Central note for SAP NetWeaver 7.31 SP26 Application Server Java
Affected components
- ESREG-SERVICES: from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
Full note on SAP: SAP Support Launchpad note 2800779
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
