216.73.217.22

CVE-2024-42374

· Published 13/08/2024 04:15 · Modified 13/08/2024 12:58

Labels: CVE-2024-42374 2024-08-13CVE-2024-42374CWE-91[email protected]

Essential information

Published
13/08/2024 04:15
Modified
13/08/2024 12:58
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

CVSS metrics

Description

BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve information from the SAP ADS system and exhaust the number of XMLForm service which makes the SAP ADS rendering (PDF creation) unavailable. This affects the confidentiality and availability of the application.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References