CVE-2024-34683
Unrestricted file upload in SAP Document Builder (HTTP service)
An authenticated attacker can upload malicious
file to SAP Document Builder service. When the victim accesses this file, the
attacker is allowed to access, modify, or make the related information
unavailable in the victim’s browser.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Affected products
SAP_SE · SAP Document BuilderWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →