CVE-2024-34683

MEDIUM

SAP Document Builder - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0026
EPSS Percentile 48.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (14)
sap/document_builder 101
sap/document_builder 103
sap/document_builder 104
sap/document_builder 105
sap/document_builder 106
sap/document_builder 107
sap/document_builder 108
sap/document_builder 731
sap/document_builder 746
sap/document_builder 747
... and 4 more
Published Jun 11, 2024
Tracked Since Feb 18, 2026