Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0393 SQL Injection vulnerability in SAP Quality Management, SAP security note 2816035

SAP Note 2816035
Medium priority

SAP security note 2816035, "[CVE-2019-0393] SQL Injection vulnerability in SAP Quality Management", released on 12.11.2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentQuality Management (QM)
PriorityCorrection with medium priority
StatusReleased for Customer
Released on12.11.2019

Description

Symptom

A SQL Injection vulnerability has been identified in SAP Quality Management (QM), allowing attackers to perform targeted database queries that can read historical inspection results. This vulnerability is referenced as CVE-2019-0393.

  • Database Manipulation: Access unauthorized information.
  • Data Integrity: Read or delete data by gaining privileges to the database.

Solution

This issue has been addressed by ensuring that input parameters are properly quoted to prevent SQL injection attacks.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Affected components

  • S4CORE 100 to 103

Full note on SAP: SAP Support Launchpad note 2816035

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More