Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0308 Code Injection vulnerability in SAP E-Commerce (Business-to-Consumer) Application, SAP security note 2773493

SAP Note 2773493

SAP security note 2773493, "[CVE-2019-0308] Code Injection vulnerability in SAP E-Commerce (Business-to-Consumer) Application", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP E-Commerce (Business-to-Consumer) application allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Some well-known impacts of Code Injection vulnerability are:

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

This note contains Java Correction(s) for E-Commerce / Web Channel. Implement the SP Patch Level attached to this note. For further information about installing Java Patches consult note 877887. Information about the patch strategy can be found in note 1546959.

Reason and prerequisites

Insufficient input validation.

CVSS

Score 6.8 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

References

Affected components

  • SAP-CRMJAV: 730, 731, 732, 733, 754
  • SAP-CRMWEB: 730, 731, 732, 733, 754
  • SAP-SHRWEB: 730, 731, 732, 733, 754
  • SAP-SHRJAV: 730, 731, 732, 733, 754
  • SAP-CRMAPP: 730, 731, 732, 733, 754
  • SAP-SHRAPP: 730, 731, 732, 733, 754

Full note on SAP: SAP Support Launchpad note 2773493

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More