CVE-2019-0304: SAP Advanced Business Application Programming Platform Kernel

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.

Affected products

  • SAP Advanced Business Application Programming Platform Kernel: version 7.21 only; version 7.45 only; version 7.49 only; version 7.53 only; version 7.73 only
  • SAP Advanced Business Application Programming Platform KRNL32NUC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only
  • SAP Advanced Business Application Programming Platform KRNL32UC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only
  • SAP Advanced Business Application Programming Platform KRNL64NUC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only; version 7.49 only
  • SAP Advanced Business Application Programming Platform KRNL64UC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only; version 7.49 only; version 7.73 only

Published 2019-06-12. Last modified 2026-06-17.