cve/2024/CVE-2024-42374.md
2025-09-29 21:09:30 +02:00

1.7 KiB

CVE-2024-42374

Description

BEx Web Java Runtime Export Web Service does notsufficiently validate an XML document accepted from an untrusted source. Anattacker can retrieve information from the SAP ADS system and exhaust thenumber of XMLForm service which makes the SAP ADS rendering (PDF creation)unavailable. This affects the confidentiality and availability of theapplication.

POC

Reference

No PoCs from references.

Github