« Volver al listado

CVE-2019-0322

Estado: ModificadaAlta (7.5)—

SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-0322",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP Commerce Cloud (ex SAP Hybris Commerce) (HY_COM)",
          "versions": [
            {
              "status": "affected",
              "version": "< 6.3"
            },
            {
              "status": "affected",
              "version": "< 6.4"
            },
            {
              "status": "affected",
              "version": "< 6.5"
            },
            {
              "status": "affected",
              "version": "< 6.6"
            },
            {
              "status": "affected",
              "version": "< 6.7"
            },
            {
              "status": "affected",
              "version": "< 1808"
            },
            {
              "status": "affected",
              "version": "< 1811"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-07-10T19:15:10.377",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/109076",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2781873",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/109076",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2781873",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service."
    },
    {
      "lang": "es",
      "value": "SAP Commerce Cloud (anteriormente conocido como SAP Hybris Commerce), (HY_COM, versiones 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), permite que un atacante impida a los usuarios legítimos acceder a un servicio, ya sea bloqueando o inundando el servicio ."
    }
  ],
  "lastModified": "2026-06-17T02:08:10.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:commerce_cloud:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EAE8CBD-D611-4149-BC36-C6A0DB5E45D5"
            },
            {
              "criteria": "cpe:2.3:a:sap:commerce_cloud:6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E1C7951-7EDB-4BFC-ABF2-906778CD058F"
            },
            {
              "criteria": "cpe:2.3:a:sap:commerce_cloud:6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9D2F233-16BB-4E4F-8FA3-FB03A0C198E5"
            },
            {
              "criteria": "cpe:2.3:a:sap:commerce_cloud:6.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB45CC6E-1837-4B0A-9F78-730161506D6D"
            },
            {
              "criteria": "cpe:2.3:a:sap:commerce_cloud:6.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F32D694A-18E7-40E3-8EE0-9A240DED7A34"
            },
            {
              "criteria": "cpe:2.3:a:sap:commerce_cloud:1808:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5649AB0A-1D84-4716-A178-F196A1DA9C1A"
            },
            {
              "criteria": "cpe:2.3:a:sap:commerce_cloud:1811:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9DE60D1-95FF-4220-AE63-2C351781FDA1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}