SQL injection vulnerability in SAP Global Label Management (GLM)
Published May 14, 2024
4.2
MEDIUMCVSS 3.1
EPSS 0.29%
Description
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.
Affected products
-
Affected
- 605
- 606
- 616
- 617
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SAP SE | SAP Global Label Management (GLM) | unaffected | Affected
|
No data.
-
Affected
- 605
- 606
- 616
- 617
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SAP | Global Label Management | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data