First published: Wed Dec 11 2019(Updated: )
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Enable Now | <1911 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0403 is a vulnerability in SAP Enable Now before version 1911 that allows an attacker to input commands into CSV files, which are executed when opened, leading to CSV Command Injection.
CVE-2019-0403 has a severity rating of 9.8 (critical).
SAP Enable Now before version 1911 is affected by CVE-2019-0403.
An attacker can exploit CVE-2019-0403 by inputting commands into CSV files, which will be executed when opened.
Yes, applying the latest version (1911 or later) of SAP Enable Now will fix CVE-2019-0403.