CVE-2019-0304 Information
Feb 14, 2021
cve
Description
FTP Function of SAP NetWeaver AS ABAP Platform versions- KRNL32NUC 7.21 7.21EXT 7.22 7.22EXT KRNL32UC 7.21 7.21EXT 7.22 7.22EXT KRNL64NUC 7.21 7.21EXT 7.22 7.22EXT 7.49 KRNL64UC 7.21 7.21EXT 7.22 7.22EXT 7.49 7.73 KERNEL 7.21 7.45 7.49 7.53 7.73 allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://launchpad.support.sap.com//notes/2719530 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: