ZeroHour

CVE-2019-0344

KEVmoderate

Unauthenticated Deserialization RCE in SAP Commerce Cloud (virtualjdbc)

CISA: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
7%p94
Published
()
KEV added
AI analysis

SAP Commerce Cloud releases 6.4, 6.5, 6.6, 6.7, 1808, 1811 and 1905 use unsafe deserialization of untrusted data in the virtualjdbc extension, letting attackers who can reach that component over the network inject and execute arbitrary code. No authentication or user interaction is required, which is reflected in the critical 9.8 CVSS 3.1 score. Successful exploitation yields code execution under the 'Hybris' user account on the target machine, enough to compromise the commerce platform and pivot further into the environment. Any organization running one of the listed SAP Commerce versions with the virtualjdbc extension deployed is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-30, confirming exploitation in the wild, although no public proof-of-concept is known.

What to do: Upgrade affected SAP Commerce releases (6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905) to the patched patch levels per SAP's security advisory for CVE-2019-0344, or move to a current supported release. If patching is delayed, restrict network access to the virtualjdbc extension or remove it if unused, and verify whether it is exposed to the internet. Given the KEV listing, review logs for suspicious requests to the virtualjdbc endpoint and unexpected processes running as the 'Hybris' user; federal agencies must apply vendor mitigations or discontinue use of the product.

Affected
SAP Commerce Cloud (virtualjdbc extension)6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905
Estimated exposure
moderatelikely in the low thousands of installations; internet-exposed subset unknown — SAP Commerce (formerly Hybris) is enterprise e-commerce software deployed mainly by large retail and B2B organizations, typically with multiple environments per customer, but no public scan data exists on how many instances have the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.

CISA Known Exploited Vulnerability
Affected
SAP Commerce Cloud
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sap
Products
commerce cloud
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news