CVE-2019-0343: SAP Commerce Cloud
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
Affected products
- SAP Commerce Cloud: version 6.4 only; version 6.5 only; version 6.6 only; version 6.7 only; version 1808 only; version 1811 only; …
Published 2019-08-14. Last modified 2026-06-17.