« Volver al listado

CVE-2023-41369

Estado: ModificadaMedia (4.3)—

The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-41369",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-41369",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-25T15:11:16.316030Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "SAP S/4HANA (Create Single Payment application)",
          "versions": [
            {
              "status": "affected",
              "version": "100"
            },
            {
              "status": "affected",
              "version": "101"
            },
            {
              "status": "affected",
              "version": "102"
            },
            {
              "status": "affected",
              "version": "103"
            },
            {
              "status": "affected",
              "version": "104"
            },
            {
              "status": "affected",
              "version": "105"
            },
            {
              "status": "affected",
              "version": "106"
            },
            {
              "status": "affected",
              "version": "107"
            },
            {
              "status": "affected",
              "version": "108"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-09-12T02:15:12.983",
  "references": [
    {
      "url": "https://me.sap.com/notes/3369680",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://me.sap.com/notes/3369680",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.\n\n"
    },
    {
      "lang": "es",
      "value": "La aplicación Create Single Payment de SAP S/4HANA - versiones 100, 101, 102, 103, 104, 105, 106, 107, 108, permite a un atacante cargar el archivo XML como datos adjuntos. Cuando se hace clic en el archivo XML en la sección de datos adjuntos, el archivo se abre en el navegador para hacer que los bucles de entidad ralenticen el navegador."
    }
  ],
  "lastModified": "2026-06-17T06:22:01.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:100:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D978AA69-72A7-4A7E-B3A1-8D342B4B77CE"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:101:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A800EB9-BD11-46B8-9866-31088F01D433"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:102:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EE80980-12A5-40D7-8992-5C81FC82935E"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:103:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82AAE66A-7112-4E83-9094-2AA571144F64"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:104:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFF0FD31-F4F3-470A-9CB5-DE339D7334FF"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:105:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A52E5AE7-D16E-4122-A39E-20A2CAB9A146"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:106:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAEF60F9-E053-4D22-AA65-9C1CA5130374"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:107:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8606117E-F864-474F-8839-F6BAB51113E0"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:108:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F794CB63-BF34-42D5-9998-CD2F2B2FF25F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}