4.3

CVE-2023-41369

External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)

The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ S/4 Hana Version 100
SAP ≫ S/4 Hana Version 101
SAP ≫ S/4 Hana Version 102
SAP ≫ S/4 Hana Version 103
SAP ≫ S/4 Hana Version 104
SAP ≫ S/4 Hana Version 105
SAP ≫ S/4 Hana Version 106
SAP ≫ S/4 Hana Version 107
SAP ≫ S/4 Hana Version 108
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.329
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
SAP 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Vendor Advisory
https://me.sap.com/notes/3369680
Permissions Required