Vulnerability Description
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | 7.10 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2798336Permissions RequiredThird Party Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=525962506Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2798336Permissions RequiredThird Party Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=525962506Third Party Advisory
FAQ
What is CVE-2019-0355?
CVE-2019-0355 is a vulnerability with a CVSS score of 7.2 (HIGH). SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code ...
How severe is CVE-2019-0355?
CVE-2019-0355 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0355?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Java.