FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.
References
| Link | Resource |
|---|---|
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242 | Vendor Advisory |
| https://launchpad.support.sap.com/#/notes/2719530 | Permissions Required Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-06-12 15:29
Updated : 2021-07-21 11:39
NVD link : CVE-2019-0304
Mitre link : CVE-2019-0304
JSON object : View
Products Affected
sap
- advanced_business_application_programming_platform_krnl32nuc
- advanced_business_application_programming_platform_krnl32uc
- advanced_business_application_programming_platform_kernel
- advanced_business_application_programming_platform_krnl64nuc
- advanced_business_application_programming_platform_krnl64uc
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
