Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2024-39591
Disclosure Date: August 13, 2024 (last updated September 13, 2024)
SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.
0
Attacker Value
Unknown
CVE-2024-34683
Disclosure Date: June 11, 2024 (last updated August 10, 2024)
An authenticated attacker can upload malicious
file to SAP Document Builder service. When the victim accesses this file, the
attacker is allowed to access, modify, or make the related information
unavailable in the victim’s browser.
0