4.3
CVE-2024-41731
- EPSS 0.51%
- Veröffentlicht 13.08.2024 04:15:08
- Zuletzt bearbeitet 10.12.2024 07:15:06
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can cause a low impact on the Integrity of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Business Objects Business Intelligence Platform Version430
SAP ≫ Business Objects Business Intelligence Platform Version440
SAP ≫ Business Objects Business Intelligence Platform Versionenterprise_420
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.51% | 0.653 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
cna@sap.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.