cvelist/2019/0xxx/CVE-2019-0328.json

93 lines
3.5 KiB
JSON
Raw Normal View History

2018-11-26 08:03:09 -05:00
{
2019-07-10 20:00:48 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
2019-03-18 01:29:16 +00:00
"CVE_data_meta": {
"ID": "CVE-2019-0328",
2019-07-10 20:00:48 +00:00
"ASSIGNER": "cna@sap.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "SAP SE",
"product": {
"product_data": [
{
"product_name": "SAP NetWeaver Process Integration ABAP tests (SAP Basis)",
"version": {
"version_data": [
{
"version_name": "<",
"version_value": "7.0"
},
{
"version_name": "<",
"version_value": "7.1"
},
{
"version_name": "<",
"version_value": "7.3"
},
{
"version_name": "<",
"version_value": "7.31"
},
{
"version_name": "<",
"version_value": "7.4"
},
{
"version_name": "<",
"version_value": "7.5"
}
]
}
}
]
}
}
]
}
2019-03-18 01:29:16 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2019-07-10 20:00:48 +00:00
"value": "ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Code Injection"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "BID",
"name": "109067",
"url": "http://www.securityfocus.com/bid/109067"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2774489",
"refsource": "MISC",
"name": "https://launchpad.support.sap.com/#/notes/2774489"
},
{
"refsource": "CONFIRM",
"name": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575",
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575"
2019-03-18 01:29:16 +00:00
}
]
}
}