CVE-2019-0344
KEVmoderateUnauthenticated Deserialization RCE in SAP Commerce Cloud (virtualjdbc)
CISA: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
SAP Commerce Cloud releases 6.4, 6.5, 6.6, 6.7, 1808, 1811 and 1905 use unsafe deserialization of untrusted data in the virtualjdbc extension, letting attackers who can reach that component over the network inject and execute arbitrary code. No authentication or user interaction is required, which is reflected in the critical 9.8 CVSS 3.1 score. Successful exploitation yields code execution under the 'Hybris' user account on the target machine, enough to compromise the commerce platform and pivot further into the environment. Any organization running one of the listed SAP Commerce versions with the virtualjdbc extension deployed is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-30, confirming exploitation in the wild, although no public proof-of-concept is known.
What to do: Upgrade affected SAP Commerce releases (6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905) to the patched patch levels per SAP's security advisory for CVE-2019-0344, or move to a current supported release. If patching is delayed, restrict network access to the virtualjdbc extension or remove it if unused, and verify whether it is exposed to the internet. Given the KEV listing, review logs for suspicious requests to the virtualjdbc endpoint and unexpected processes running as the 'Hybris' user; federal agencies must apply vendor mitigations or discontinue use of the product.
| SAP Commerce Cloud (virtualjdbc extension) | 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
- Affected
- SAP Commerce Cloud
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- commerce cloud
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H