CVE-2024-34683 describes a vulnerability in SAP Document Builder where an authenticated attacker can upload malicious files. When a victim accesses these files, the attacker can compromise the victim's browser, leading to unauthorized access, modification, or denial of service for related information. With a CVSS score of 6.5 (Medium), this vulnerability requires user interaction and low privileges but can result in low impact to confidentiality, integrity, and availability. There is currently no public exploit code available, and the vulnerability shows minimal community discussion or media coverage, indicating low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
101CPE matchmatch criteria | cpe:2.3:a:sap:document_builder:101:*:*:*:*:*:*:* | ||
103CPE matchmatch criteria | cpe:2.3:a:sap:document_builder:103:*:*:*:*:*:*:* | ||
104CPE matchmatch criteria | cpe:2.3:a:sap:document_builder:104:*:*:*:*:*:*:* | ||
105CPE matchmatch criteria | cpe:2.3:a:sap:document_builder:105:*:*:*:*:*:*:* | ||
106CPE matchmatch criteria | cpe:2.3:a:sap:document_builder:106:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.