Medium priority
SAP security note 2816035, "[CVE-2019-0393] SQL Injection vulnerability in SAP Quality Management", released on 12.11.2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A SQL Injection vulnerability has been identified in SAP Quality Management (QM), allowing attackers to perform targeted database queries that can read historical inspection results. This vulnerability is referenced as CVE-2019-0393.
- Database Manipulation: Access unauthorized information.
- Data Integrity: Read or delete data by gaining privileges to the database.
Solution
This issue has been addressed by ensuring that input parameters are properly quoted to prevent SQL injection attacks.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Affected components
- S4CORE 100 to 103
Full note on SAP: SAP Support Launchpad note 2816035
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
