SAP released 11 Security Notes as part of the Patch Day July 2019. One of them addresses a critical vulnerability in Diagnostics Agent tracked as CVE-2019-0330. The vulnerability is an OS command injection issue that could be exploited to fully compromise the SAP system. Experts pointed out that the SDMAgent must be installed in every SAP system for diagnostic purposes, this means that the extent of the attack is broad and could affect the entire landscape. The flaw resides in the Extended Computer Aided Test Tool (eCATT)”]
Source: https://securityaffairs.co/wordpress/88396/security/sap-security-notes-july-2019.html

