VulnerabilityModified
CVE-2019-0247
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application.
CRITICAL 9.8EPSS 1.27%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- sap/cloud connector
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2696233Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=509151985Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2696233Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=509151985Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.