First published: Wed Nov 13 2019(Updated: )
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Quality Management | =1.0 | |
SAP Quality Management | =1.01 | |
SAP Quality Management | =1.02 | |
SAP Quality Management | =1.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0393 is classified as a high severity SQL Injection vulnerability.
To fix CVE-2019-0393, upgrade SAP Quality Management to versions 1.0, 1.01, 1.02, or 1.03 or later.
CVE-2019-0393 allows attackers to perform targeted database queries that can expose sensitive historical inspection results.
Yes, CVE-2019-0393 affects SAP Quality Management versions prior to 1.0 and subsequent patched versions.
Organizations using vulnerable versions of SAP Quality Management are at risk of exploitation through CVE-2019-0393.