CVE-2024-34692
CVSS V2 None
CVSS V3 None
Description
Due to missing verification of file type or
content, SAP Enable Now allows an authenticated attacker to upload arbitrary
files. These files include executables which might be downloaded and executed
by the user which could host malware. On successful exploitation an attacker
can cause limited impact on confidentiality and Integrity of the application.
Overview
- CVE ID
- CVE-2024-34692
- Assigner
- sap
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-09T04:43:05.361Z
- Last Modified Date
- 2024-07-09T04:43:05.361Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://url.sap/sapsecuritypatchday | |
https://me.sap.com/notes/3476340 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-34692 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34692 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-09 13:15:58 | Added to TrackCVE |