CVE-2019-0330: SAP Diagnostics Agent
Critical severity, CVSS 9.1. EPSS: 2.2% chance of exploitation in the next 30 days.
The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Affected products
- SAP Diagnostics Agent: version 7.20 only
Published 2019-07-10. Last modified 2026-06-17.