Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23851

Опубликовано: 14 фев. 2023
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:business_planning_and_consolidation:200:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:300:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00209
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 5.4
github
почти 3 года назад

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.

EPSS

Процентиль: 43%
0.00209
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-434