6.5

CVE-2024-34683

Unrestricted file upload in SAP Document Builder (HTTP service)

An authenticated attacker can upload malicious
file to SAP Document Builder service. When the victim accesses this file, the
attacker is allowed to access, modify, or make the related information
unavailable in the victim’s browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Document Builder Version 101
SAP ≫ Document Builder Version 103
SAP ≫ Document Builder Version 104
SAP ≫ Document Builder Version 105
SAP ≫ Document Builder Version 106
SAP ≫ Document Builder Version 107
SAP ≫ Document Builder Version 108
SAP ≫ Document Builder Version 731
SAP ≫ Document Builder Version 746
SAP ≫ Document Builder Version 747
SAP ≫ Document Builder Version 748
SAP ≫ Document Builder Version s4core_100
SAP ≫ Document Builder Version s4fnd_102
SAP ≫ Document Builder Version sap_bs_fnd_702
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.15
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.3 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
SAP 6.5 2.3 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html
Patch
Vendor Advisory
https://me.sap.com/notes/3459379
Permissions Required