Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0228

Published May 17, 2024·Last modified May 17, 2024
Description
Feiten

SAP heeft kwetsbaarheden verholpen in diverse producten, zoals NetWeaver, Business Objects, HANA en SAP GUI.

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Cross-Site-Scripting (XSS)
  • Denial-of-Service (DoS)
  • Manipulatie van gegevens
  • Omzeilen van authenticatie
  • (Remote) code execution (Gebruikersrechten)
  • SQL Injection
  • Toegang tot gevoelige gegevens
Oplossingen

SAP heeft updates beschikbaar gesteld om de kwetsbaarheden te verhelpen in de getroffen producten. Zie bijgevoegde referenties voor meer informatie:

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/may-2024.html

Kans

medium

Schade

high

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-862

Missing Authorization

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-922

Insecure Storage of Sensitive Information

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard