Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29109


The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application.


Published

2023-04-11T03:15:07.927

Last Modified

2024-11-21T07:56:33.963

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1236

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap abap_platform 75c Yes
Application sap abap_platform 75d Yes
Application sap abap_platform 75e Yes
Application sap application_interface_framework aif_703 Yes
Application sap application_interface_framework aifx_702 Yes
Application sap basis 755 Yes
Application sap basis 756 Yes
Application sap s4core 101 Yes

References