6.5

CVE-2024-34683

An authenticated attacker can upload malicious
file to SAP Document Builder service. When the victim accesses this file, the
attacker is allowed to access, modify, or make the related information
unavailable in the victim’s browser.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPDocument Builder Version101
SAPDocument Builder Version103
SAPDocument Builder Version104
SAPDocument Builder Version105
SAPDocument Builder Version106
SAPDocument Builder Version107
SAPDocument Builder Version108
SAPDocument Builder Version731
SAPDocument Builder Version746
SAPDocument Builder Version747
SAPDocument Builder Version748
SAPDocument Builder Versions4core_100
SAPDocument Builder Versions4fnd_102
SAPDocument Builder Versionsap_bs_fnd_702
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.3 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
cna@sap.com 6.5 2.3 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.