VYPR
Unrated severityNVD Advisory· Published Jul 9, 2024· Updated Aug 2, 2024

[CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now

CVE-2024-34692

Description

Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker can cause limited impact on confidentiality and Integrity of the application.

Affected products

2
  • SAP/Enable Nowllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: WPB_MANAGER_CE 10

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.