Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-0308

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.8%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 3.5
Products affected by CVE-2019-0308
  • Sap » E-Commerce » Version: 7.30
    cpe:2.3:a:sap:e-commerce:7.30
  • Sap » E-Commerce » Version: 7.31
    cpe:2.3:a:sap:e-commerce:7.31
  • Sap » E-Commerce » Version: 7.32
    cpe:2.3:a:sap:e-commerce:7.32
  • Sap » E-Commerce » Version: 7.33
    cpe:2.3:a:sap:e-commerce:7.33
  • Sap » E-Commerce » Version: 7.54
    cpe:2.3:a:sap:e-commerce:7.54


Contact Us

Shodan ® - All rights reserved