Low severity3.5NVD Advisory· Published Sep 12, 2023· Updated Jun 17, 2026
CVE-2023-41369
CVE-2023-41369
Description
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.
Affected products
12cpe:2.3:a:sap:s\/4_hana:100:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:sap:s\/4_hana:100:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:101:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:102:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:103:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:104:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:105:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:106:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:107:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s\/4_hana:108:*:*:*:*:*:*:*
- Range: 100, 101, 102, 103, 104, 105, 106, 107, 108
- SAP_SE/SAP S/4HANA (Create Single Payment application)v5Range: 100
Patches
Vulnerability mechanics
References
2- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
- me.sap.com/notes/3369680nvdPermissions Required
News mentions
0No linked articles in our index yet.