Vulnerabilities > SAP > Commerce Cloud > 6.5

DATE CVE VULNERABILITY TITLE RISK
2019-08-14 CVE-2019-0344 Deserialization of Untrusted Data vulnerability in SAP Commerce Cloud
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
network
low complexity
sap CWE-502
7.5
2019-08-14 CVE-2019-0343 Code Injection vulnerability in SAP Commerce Cloud
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection.
network
low complexity
sap CWE-94
6.5
2019-07-10 CVE-2019-0322 Unspecified vulnerability in SAP Commerce Cloud
SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
network
low complexity
sap
5.0