Vulnerability Description
The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Diagnostics Agent | 7.20 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/109068Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2808158Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575Vendor Advisory
- http://www.securityfocus.com/bid/109068Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2808158Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575Vendor Advisory
FAQ
What is CVE-2019-0330?
CVE-2019-0330 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application...
How severe is CVE-2019-0330?
CVE-2019-0330 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-0330?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Diagnostics Agent.