- Description
- An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.
- Source
- cna@sap.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
- nvd@nist.gov
- CWE-89
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:quality_management:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0600F296-CF2A-488C-A09B-1EDC66AFA115"
},
{
"criteria": "cpe:2.3:a:sap:quality_management:1.01:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A901E9B0-A2A3-4F05-AFE4-BB4749A4EEE4"
},
{
"criteria": "cpe:2.3:a:sap:quality_management:1.02:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71BF779F-8AE4-4C69-994B-0647E0115E2F"
},
{
"criteria": "cpe:2.3:a:sap:quality_management:1.03:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB2C1783-4E5B-4FD0-94C5-B1093BF6C594"
}
],
"operator": "OR"
}
]
}
]