Loading
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
Use CWE-502, Sap vendor hub and Commerce Cloud product page to widen CVE-2019-0344 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-6238, CVE-2023-39439 and CVE-2023-42481 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.