6.5
CVE-2024-34683
- EPSS 0.24%
- Veröffentlicht 11.06.2024 03:15:10
- Zuletzt bearbeitet 21.11.2024 09:19:11
- Erkennungen
Unrestricted file upload in SAP Document Builder (HTTP service)
An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Document Builder Version 101
SAP ≫ Document Builder Version 103
SAP ≫ Document Builder Version 104
SAP ≫ Document Builder Version 105
SAP ≫ Document Builder Version 106
SAP ≫ Document Builder Version 107
SAP ≫ Document Builder Version 108
SAP ≫ Document Builder Version 731
SAP ≫ Document Builder Version 746
SAP ≫ Document Builder Version 747
SAP ≫ Document Builder Version 748
SAP ≫ Document Builder Version s4core_100
SAP ≫ Document Builder Version s4fnd_102
SAP ≫ Document Builder Version sap_bs_fnd_702
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.15 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.3 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
|
| SAP | 6.5 | 2.3 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html
https://me.sap.com/notes/3459379