CVE-2019-0403: SAP Enable Now

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.

Affected products

  • SAP Enable Now: before 1911 (fixed in 1911)

Published 2019-12-11. Last modified 2026-06-17.