CVE-2019-0304
CVE-2019-0304
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Jun 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.
Affected products
SAP SE · SAP NetWeaver AS ABAP Platform(KERNEL)SAP SE · SAP NetWeaver AS ABAP Platform(KRNL32NUC)SAP SE · SAP NetWeaver AS ABAP Platform(KRNL32UC)SAP SE · SAP NetWeaver AS ABAP Platform(KRNL64NUC)SAP SE · SAP NetWeaver AS ABAP Platform(KRNL64UC)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →