CVE-2019-0355
CVE-2019-0355
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Sep 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
Affected products
SAP SE · SAP NetWeaver AS for Java (Web Container)-ENGINEAPISAP SE · SAP NetWeaver AS for Java (Web Container)-SAP-JEECORWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →