SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
References
| Link | Resource |
|---|---|
| https://launchpad.support.sap.com/#/notes/2798336 | Permissions Required Third Party Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=525962506 | Third Party Advisory |
| https://launchpad.support.sap.com/#/notes/2798336 | Permissions Required Third Party Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=525962506 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-09-10 17:15
Updated : 2024-11-21 04:16
NVD link : CVE-2019-0355
Mitre link : CVE-2019-0355
CVE.ORG link : CVE-2019-0355
JSON object : View
Products Affected
sap
- netweaver_application_server_java
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
