« Volver al listado

CVE-2024-34683

Estado: ModificadaMedia (6.5)—

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-34683",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-34683",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-11T13:35:39.111955Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "SAP Document Builder",
          "versions": [
            {
              "status": "affected",
              "version": "S4CORE 100"
            },
            {
              "status": "affected",
              "version": "101"
            },
            {
              "status": "affected",
              "version": "S4FND 102"
            },
            {
              "status": "affected",
              "version": "103"
            },
            {
              "status": "affected",
              "version": "104"
            },
            {
              "status": "affected",
              "version": "105"
            },
            {
              "status": "affected",
              "version": "106"
            },
            {
              "status": "affected",
              "version": "107"
            },
            {
              "status": "affected",
              "version": "108"
            },
            {
              "status": "affected",
              "version": "SAP_BS_FND 702"
            },
            {
              "status": "affected",
              "version": "731"
            },
            {
              "status": "affected",
              "version": "746"
            },
            {
              "status": "affected",
              "version": "747"
            },
            {
              "status": "affected",
              "version": "748"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-06-11T03:15:10.623",
  "references": [
    {
      "url": "https://me.sap.com/notes/3459379",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://me.sap.com/notes/3459379",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authenticated attacker can upload malicious\nfile to SAP Document Builder service. When the victim accesses this file, the\nattacker is allowed to access, modify, or make the related information\nunavailable in the victim’s browser."
    },
    {
      "lang": "es",
      "value": "Un atacante autenticado puede cargar un archivo malicioso en el servicio SAP Document Builder. Cuando la víctima accede a este archivo, el atacante puede acceder, modificar o hacer que la información relacionada no esté disponible en el navegador de la víctima."
    }
  ],
  "lastModified": "2026-06-17T07:33:52.247",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:document_builder:101:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5350CBE5-1DC2-4385-BB54-CF00158A0E41"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:103:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AACFC047-8DF1-4A7A-8678-B06DA5FDB813"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:104:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFEBE181-4350-4629-947E-04ED3CE715F9"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:105:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1C51CE6-E2A3-4100-A45E-5BE6997BF5CD"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:106:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36E9BCB7-A284-4F3E-8894-A6BB02294959"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:107:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9766F9DB-CF4F-45E3-B040-3962DBACECF6"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:108:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7B2AFEF-DE52-4D22-A67F-E85F7CACA118"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:731:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C930294-CB73-4D42-A406-8579B60E43B8"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:746:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AA983A4-C5D1-4757-BE08-224F69380A7D"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:747:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AFD8074-7613-4E8A-B69E-691813EAC685"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:748:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "662FF019-5901-4B3A-B5F6-CDFC9065783B"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:s4core_100:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A2A67C2-2564-4F41-BE38-C33D2C7CF9E7"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:s4fnd_102:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3273C74F-E5FE-47A2-B7F8-E76095A64359"
            },
            {
              "criteria": "cpe:2.3:a:sap:document_builder:sap_bs_fnd_702:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A14342E-3477-457C-AF13-54AFFA9DE1C0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}