CVE-2019-0393
Summary
| CVE | CVE-2019-0393 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-13 22:15:00 UTC |
| Updated | 2019-11-15 19:41:00 UTC |
| Description | An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Quality Management | 1.0 | All | All | All |
| Application | Sap | Quality Management | 1.01 | All | All | All |
| Application | Sap | Quality Management | 1.02 | All | All | All |
| Application | Sap | Quality Management | 1.03 | All | All | All |
| Application | Sap | Quality Management | 1.0 | All | All | All |
| Application | Sap | Quality Management | 1.01 | All | All | All |
| Application | Sap | Quality Management | 1.02 | All | All | All |
| Application | Sap | Quality Management | 1.03 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – November 2019 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.