PT-2024-4591 · Sap · Sap Document Builder

Published

2024-05-07

·

Updated

2024-08-09

·

CVE-2024-34683

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: SAP Document Builder (affected versions not specified)
Description: The issue is related to an unlimited upload of dangerous file types in the SAP Document Builder. An authenticated attacker can upload a malicious file to the SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-05097
CVE-2024-34683

Affected Products

Sap Document Builder