CVE-2023-41369
Estado: ModificadaMedia (4.3)—
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.49%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-611
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-41369",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-41369",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-25T15:11:16.316030Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@sap.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.5,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP_SE",
"product": "SAP S/4HANA (Create Single Payment application)",
"versions": [
{
"status": "affected",
"version": "100"
},
{
"status": "affected",
"version": "101"
},
{
"status": "affected",
"version": "102"
},
{
"status": "affected",
"version": "103"
},
{
"status": "affected",
"version": "104"
},
{
"status": "affected",
"version": "105"
},
{
"status": "affected",
"version": "106"
},
{
"status": "affected",
"version": "107"
},
{
"status": "affected",
"version": "108"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-09-12T02:15:12.983",
"references": [
{
"url": "https://me.sap.com/notes/3369680",
"tags": [
"Permissions Required"
],
"source": "cna@sap.com"
},
{
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://me.sap.com/notes/3369680",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@sap.com",
"description": [
{
"lang": "en",
"value": "CWE-611"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.\n\n"
},
{
"lang": "es",
"value": "La aplicación Create Single Payment de SAP S/4HANA - versiones 100, 101, 102, 103, 104, 105, 106, 107, 108, permite a un atacante cargar el archivo XML como datos adjuntos. Cuando se hace clic en el archivo XML en la sección de datos adjuntos, el archivo se abre en el navegador para hacer que los bucles de entidad ralenticen el navegador."
}
],
"lastModified": "2026-06-17T06:22:01.820",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:100:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D978AA69-72A7-4A7E-B3A1-8D342B4B77CE"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:101:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A800EB9-BD11-46B8-9866-31088F01D433"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:102:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7EE80980-12A5-40D7-8992-5C81FC82935E"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:103:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "82AAE66A-7112-4E83-9094-2AA571144F64"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:104:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFF0FD31-F4F3-470A-9CB5-DE339D7334FF"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:105:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A52E5AE7-D16E-4122-A39E-20A2CAB9A146"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:106:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAEF60F9-E053-4D22-AA65-9C1CA5130374"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:107:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8606117E-F864-474F-8839-F6BAB51113E0"
},
{
"criteria": "cpe:2.3:a:sap:s\\/4_hana:108:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F794CB63-BF34-42D5-9998-CD2F2B2FF25F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}