An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.
2019-11-13T22:15:11.850
2024-11-21T04:16:47.457
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | quality_management | 1.0 | Yes |
Application | sap | quality_management | 1.01 | Yes |
Application | sap | quality_management | 1.02 | Yes |
Application | sap | quality_management | 1.03 | Yes |