Vulnerability Intelligence Report
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
CVE-2019-0344
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:7.08%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502 Deserialization of Untrusted Data
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP SE | SAP Commerce Cloud (virtualjdbc extension) | < 6.4 (affected), < 6.5 (affected), < 6.6 (affected), < 6.7 (affected), < 1808 (affected), < 1811 (affected), < 1905 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2018-11-26T00:00:00 |
| Published | 2019-08-14T13:53:21 |
| Last Updated | 2025-10-21T23:45:32 |
Community Chatter & Buzz