Critical severity9.1NVD Advisory· Published Jul 10, 2019· Updated Jun 17, 2026
CVE-2019-0330
CVE-2019-0330
Description
The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Affected products
3- SAP SE/SAP Diagnostic Agent (LM-Service)v5Range: < 7.20
cpe:2.3:a:sap:diagnostics_agent:7.20:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:diagnostics_agent:7.20:*:*:*:*:*:*:*
- (no CPE)range: 7.2
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/109068nvdThird Party AdvisoryVDB Entry
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.