Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0351 Remote Code Execution(RCE) in SAP NetWeaver UDDI Server (Services Registry), SAP security note 2800779

SAP Note 2800779
SAP Security Note
HotNews

SAP security note 2800779, "[CVE-2019-0351] Remote Code Execution(RCE) in SAP NetWeaver UDDI Server (Services Registry)", is a program error note released on August 13, 2019. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onAugust 13, 2019

Description

Symptom

A Remote Code Execution vulnerability exists in the Services Registry. An attacker can exploit this vulnerability to take complete control of the product, including viewing, changing, or deleting data by injecting code into the working memory, which is subsequently executed by the application. It can also cause the product to terminate unexpectedly.

Solution

Please apply the provided patch.

CVSS

Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

Affected components

  • ESREG-SERVICES: from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50

Full note on SAP: SAP Support Launchpad note 2800779

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More