← Back

CVE-2024-34683

nvd nist
Published: Jun 11, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Exploitability: 2.3 / Impact: 3.7
Source: NVD

Description

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser.

Affected (14)

1 product
Document Builder
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 101
Version 103
Version 104
Version 105
Version 106
Version 107
Version 108
Version 731
Version 746
Version 747
Version 748
Version s4core_100
Version s4fnd_102
Version sap_bs_fnd_702

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.