PT-2023-27932 · Sap · Sap S/4Hana
CVE-2023-41369
·
Publicado
2023-09-11
·
Atualizado
2023-09-14
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
SAP S/4HANA versions 100 through 108
Description
The issue allows an attacker to upload an XML file as an attachment in the Create Single Payment application. When the XML file is clicked on in the attachment section, it opens in the browser and can cause entity loops, slowing down the browser.
Recommendations
For SAP S/4HANA versions 100 through 108, consider restricting the upload of XML files in the Create Single Payment application to prevent potential exploitation. As a temporary workaround, avoid clicking on XML files in the attachment section to minimize the risk of browser slowdown.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap S/4Hana