LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-0344: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 30, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 21, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-0344 to its Known Exploited Vulnerabilities catalog on Sep 30, 2024, with a federal patch deadline of Oct 21, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.

CVE-2019-0344 is a deserialization of untrusted data vulnerability in SAP Commerce Cloud (formerly known as Hybris). It affects the mediaconversion and virtualjdbc extensions and allows code injection. For organizations running this e-commerce platform, the issue matters because successful abuse can let an attacker inject and run code in the application context, potentially compromising the host and any connected systems or data.

Defenders should treat it as a high-priority finding until they confirm their specific deployment is not exposed. Public detail is limited to the components named above; exact impact and prerequisites must be confirmed against the vendor advisory.

How it works

The underlying weakness is CWE-502: deserialization of untrusted data. In this class of flaw, an application accepts serialized objects from an untrusted source and reconstructs them without sufficient validation. During reconstruction, the runtime can invoke methods or constructors that an attacker controls, resulting in code injection.

According to the CISA summary, the vulnerable paths sit inside the mediaconversion and virtualjdbc extensions of SAP Commerce Cloud. An attacker who can supply crafted serialized input to those components can trigger the deserialization process and achieve code injection. No further exploit mechanics are provided in the available facts; any concrete payload format, required privileges, or network exposure must be verified in the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

SAP Commerce Cloud is typically deployed as the backend for online storefronts, product catalogs, and related commerce services. It may run on-premises, in private clouds, or as a managed service. Inventory efforts should therefore focus on any servers, containers, or cloud instances that host SAP Commerce Cloud or its predecessor Hybris.

If the product is no longer in use, confirm that residual instances have been decommissioned.

How to remediate

The primary action is to apply the mitigations or updates supplied by SAP, following the vendor instructions exactly. CISA’s required action is to apply those mitigations or discontinue use of the product if mitigations are unavailable.

Document the change and retain evidence of the update for audit purposes.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls that limit reachability and detect abuse.

These measures lower risk but do not replace the official fix.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full system compromise and subsequent data breaches. Known ransomware use is not documented for this CVE. If you suspect compromise, isolate affected hosts, preserve forensic evidence, and follow your incident-response plan. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether credentials or other information have already appeared in public leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · Commerce Cloud
WeaknessCWE-502
Added to CISA KEVSep 30, 2024
Federal patch deadlineOct 21, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities