PT-2024-26110 · Sap · Sap Enable Now

Published

2024-07-08

·

Updated

2024-09-09

·

CVE-2024-34692

CVSS v3.1

3.3

Low

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Enable Now (affected versions not specified)
Description The issue allows an authenticated attacker to upload arbitrary files, including executables, due to missing verification of file type or content. These files might be downloaded and executed by the user, potentially hosting malware. Successful exploitation can cause limited impact on confidentiality and integrity of the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-34692

Affected Products

Sap Enable Now