Lucene search

K
cveSapCVE-2019-0403
HistoryDec 11, 2019 - 10:15 p.m.

CVE-2019-0403

2019-12-1122:15:11
CWE-1236
sap
web.nvd.nist.gov
65
sap
enable now
version 1911
command injection
csv
nvd
cve-2019-0403

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.004

Percentile

73.7%

SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.

Affected configurations

Nvd
Node
sapenable_nowRange<1911
VendorProductVersionCPE
sapenable_now*cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SAP Enable Now",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "before 1911"
      }
    ]
  }
]

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.004

Percentile

73.7%

Related for CVE-2019-0403