CVE-2024-34683

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
11/06/2024
Last modified:
09/08/2024

Description

An authenticated attacker can upload malicious<br /> file to SAP Document Builder service. When the victim accesses this file, the<br /> attacker is allowed to access, modify, or make the related information<br /> unavailable in the victim’s browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:document_builder:101:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:105:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:106:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:107:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:108:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:s4core_100:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:s4fnd_102:*:*:*:*:*:*:*
cpe:2.3:a:sap:document_builder:sap_bs_fnd_702:*:*:*:*:*:*:*