CVE-2019-0344: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-09-30. EPSS: 7.1% chance of exploitation in the next 30 days.

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.

Affected products

  • SAP Commerce Cloud: version 6.4 only; version 6.5 only; version 6.6 only; version 6.7 only; version 1808 only; version 1811 only; …

Published 2019-08-14. Last modified 2026-06-17.