CVE-2026-24317
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-427
Elemento no controlado en la ruta de búsqueda
Fecha de publicación:
10/03/2026
Última modificación:
10/03/2026
Descripción
*** Pendiente de traducción *** SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided GuiXT is enabled. This vulnerability has a low impact on confidentiality, integrity, and availability.
Impacto
Puntuación base 3.x
5.00
Gravedad 3.x
MEDIA



