CVE Vulnerabilities

CVE-2023-41369

Improper Restriction of XML External Entity Reference

Published: Sep 12, 2023 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
S/4_hanaSap100 (including)100 (including)
S/4_hanaSap101 (including)101 (including)
S/4_hanaSap102 (including)102 (including)
S/4_hanaSap103 (including)103 (including)
S/4_hanaSap104 (including)104 (including)
S/4_hanaSap105 (including)105 (including)
S/4_hanaSap106 (including)106 (including)
S/4_hanaSap107 (including)107 (including)
S/4_hanaSap108 (including)108 (including)

Potential Mitigations

References