Vulnerability Description
FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Advanced Business Application Programming Platform Kernel | 7.21 |
| Sap | Advanced Business Application Programming Platform Krnl32Nuc | 7.21 |
| Sap | Advanced Business Application Programming Platform Krnl32Uc | 7.21 |
| Sap | Advanced Business Application Programming Platform Krnl64Nuc | 7.21 |
| Sap | Advanced Business Application Programming Platform Krnl64Uc | 7.21 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2719530Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2719530Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242Vendor Advisory
FAQ
What is CVE-2019-0304?
CVE-2019-0304 is a vulnerability with a CVSS score of 9.8 (CRITICAL). FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7....
How severe is CVE-2019-0304?
CVE-2019-0304 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-0304?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Advanced Business Application Programming Platform Kernel, Sap Advanced Business Application Programming Platform Krnl32Nuc, Sap Advanced Business Application Programming Platform Krnl32Uc, Sap Advanced Business Application Programming Platform Krnl64Nuc, Sap Advanced Business Application Programming Platform Krnl64Uc.