Описание
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.
Ссылки
- Permissions RequiredVendor Advisory
- Vendor Advisory
- Permissions RequiredVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1911 (исключая)
cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06684
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1236
Связанные уязвимости
github
больше 3 лет назад
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.
EPSS
Процентиль: 91%
0.06684
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1236