← Vulnerability feed

Vulnerability record · CVE-2019-0344 · published 14 August 2019

CVE-2019-0344: SAP Commerce Cloud virtualjdbc unsafe deserialization RCE

Sap · Commerce Cloud

SAP Commerce Cloud's virtualjdbc extension deserializes untrusted data without validation across versions 6.4 through 1905. An unauthenticated remote attacker can exploit this to execute arbitrary code with Hybris user rights. The flaw is critical because it is network-reachable, needs no credentials or user interaction, and is listed in CISA KEV.

9.8 CVSS 3.1 Critical CISA KEV since 30 Sep 2024 EPSS 7.1% · top 6.0% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
7.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and confirmed active exploitation in CISA KEV make this an urgent patch.

What it is

SAP Commerce Cloud's virtualjdbc extension deserializes untrusted data without validation across versions 6.4 through 1905. An unauthenticated remote attacker can exploit this to execute arbitrary code with Hybris user rights. The flaw is critical because it is network-reachable, needs no credentials or user interaction, and is listed in CISA KEV.

Impact

An attacker gains arbitrary code execution on the target host under the Hybris service account, enabling full compromise of the SAP Commerce Cloud instance and its data.

Attack surface

Reachable over the network via the virtualjdbc extension with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any exposed virtualjdbc endpoint is a candidate entry point.

Exploitation

CVE-2019-0344 is listed in CISA KEV (added 2024-09-30, due 2024-10-21), confirming active exploitation; EPSS 30-day probability is 0.07079 (93.9th percentile). No ransomware campaign use is documented.

What to do

  • Apply the SAP security note 2786035 patch for the affected Commerce Cloud versions (6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905) immediately.
  • If patching is not possible, restrict network access to the virtualjdbc extension and block untrusted deserialization endpoints at the perimeter.
  • Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
  • Verify the Hybris service account runs with least privilege to limit post-exploitation impact.
  • Monitor SAP security notes for updated guidance since the referenced wiki link is broken.

Detection

  • Monitor network traffic to virtualjdbc endpoints for serialized Java object payloads or unexpected deserialization requests.
  • Alert on child processes spawned by the Hybris/Java service account, especially shells or scripting interpreters.
  • Review application and web server logs for anomalous requests to the virtualjdbc extension path.
  • Hunt for outbound connections from the SAP Commerce Cloud host to unknown external IPs that may indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-0344 to the Known Exploited Vulnerabilities catalog on 30 September 2024 as "SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-0344 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-39439Sap commerce cloud vulnerabilitySAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphra…EPSS 0.71%9.3CVE-2020-6238Sap commerce cloud xml external entity (xxe) vulnerabilitySAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing …EPSS 1.3%9.1CVE-2024-33003Sap commerce cloud information exposure vulnerabilitySome OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number…EPSS 0.48%8.8CVE-2019-0343Sap commerce cloud code injection vulnerabilitySAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject …EPSS 1.5%8.1CVE-2023-42481Sap commerce cloud weak password recovery vulnerabilityIn SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the for…EPSS 0.52%7.5CVE-2023-37486Sap commerce cloud vulnerabilityUnder certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access informatio…EPSS 0.52%7.5CVE-2019-0322Sap commerce cloud vulnerabilitySAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent l…EPSS 2.6%6.1CVE-2021-33666Sap commerce cloud cross-site scripting vulnerabilityWhen SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used…EPSS 0.54%

Source: NIST National Vulnerability Database (record CVE-2019-0344), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.