2024-12-08 03:06:42 +00:00

72 lines
2.4 KiB
JSON

{
"id": "CVE-2024-37177",
"sourceIdentifier": "cna@sap.com",
"published": "2024-06-11T02:15:09.243",
"lastModified": "2024-11-21T09:23:22.090",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "SAP Financial Consolidation allows data to enter\na Web application through an untrusted source. These endpoints are exposed over\nthe network and it allows the user to modify the content from the web site. On\nsuccessful exploitation, an attacker can cause significant impact to\nconfidentiality and integrity of the application."
},
{
"lang": "es",
"value": "SAP Financial Consolidation permite que los datos ingresen a una aplicaci\u00f3n web a trav\u00e9s de una fuente que no es de confianza. Estos endpoints est\u00e1n expuestos a trav\u00e9s de la red y permiten al usuario modificar el contenido del sitio web. Si la explotaci\u00f3n tiene \u00e9xito, un atacante puede causar un impacto significativo en la confidencialidad y la integridad de la aplicaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@sap.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/3457592",
"source": "cna@sap.com"
},
{
"url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
"source": "cna@sap.com"
},
{
"url": "https://me.sap.com/notes/3457592",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}