Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
SAP heeft kwetsbaarheden verholpen in diverse producten, zoals NetWeaver, Business Objects, HANA en SAP GUI.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Cross-Site-Scripting (XSS)
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van authenticatie
- (Remote) code execution (Gebruikersrechten)
- SQL Injection
- Toegang tot gevoelige gegevens
- Oplossingen
SAP heeft updates beschikbaar gesteld om de kwetsbaarheden te verhelpen in de getroffen producten. Zie bijgevoegde referenties voor meer informatie:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/may-2024.html
- Kans
medium
- Schade
high
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-434
Unrestricted Upload of File with Dangerous Type
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-862
Missing Authorization
- CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CWE-922
Insecure Storage of Sensitive Information
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard