Vulnerability record · CVE-2019-0344 · published 14 August 2019
CVE-2019-0344: SAP Commerce Cloud virtualjdbc unsafe deserialization RCE
Sap · Commerce Cloud
SAP Commerce Cloud's virtualjdbc extension deserializes untrusted data without validation across versions 6.4 through 1905. An unauthenticated remote attacker can exploit this to execute arbitrary code with Hybris user rights. The flaw is critical because it is network-reachable, needs no credentials or user interaction, and is listed in CISA KEV.
Description
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and confirmed active exploitation in CISA KEV make this an urgent patch.
What it is
SAP Commerce Cloud's virtualjdbc extension deserializes untrusted data without validation across versions 6.4 through 1905. An unauthenticated remote attacker can exploit this to execute arbitrary code with Hybris user rights. The flaw is critical because it is network-reachable, needs no credentials or user interaction, and is listed in CISA KEV.
Impact
An attacker gains arbitrary code execution on the target host under the Hybris service account, enabling full compromise of the SAP Commerce Cloud instance and its data.
Attack surface
Reachable over the network via the virtualjdbc extension with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any exposed virtualjdbc endpoint is a candidate entry point.
Exploitation
CVE-2019-0344 is listed in CISA KEV (added 2024-09-30, due 2024-10-21), confirming active exploitation; EPSS 30-day probability is 0.07079 (93.9th percentile). No ransomware campaign use is documented.
What to do
- Apply the SAP security note 2786035 patch for the affected Commerce Cloud versions (6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905) immediately.
- If patching is not possible, restrict network access to the virtualjdbc extension and block untrusted deserialization endpoints at the perimeter.
- Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
- Verify the Hybris service account runs with least privilege to limit post-exploitation impact.
- Monitor SAP security notes for updated guidance since the referenced wiki link is broken.
Detection
- Monitor network traffic to virtualjdbc endpoints for serialized Java object payloads or unexpected deserialization requests.
- Alert on child processes spawned by the Hybris/Java service account, especially shells or scripting interpreters.
- Review application and web server logs for anomalous requests to the virtualjdbc extension path.
- Hunt for outbound connections from the SAP Commerce Cloud host to unknown external IPs that may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0344 to the Known Exploited Vulnerabilities catalog on 30 September 2024 as "SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 October 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://launchpad.support.sap.com/#/notes/2786035 | Permissions RequiredVendor Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 | Broken Link |
| https://launchpad.support.sap.com/#/notes/2786035 | Permissions RequiredVendor Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0344 | US Government Resource |
Track CVE-2019-0344 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0344), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.