CVE-2023-41369: External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP S/4HANA vulnerability?
The vulnerability ID for this SAP S/4HANA vulnerability is CVE-2023-41369.
What is the severity of CVE-2023-41369?
The severity of CVE-2023-41369 is medium, with a severity value of 4.3.
Which versions of SAP S/4HANA are affected by CVE-2023-41369?
The versions 100, 101, 102, 103, 104, 105, 106, 107, and 108 of SAP S/4HANA are affected by CVE-2023-41369.
What is the impact of CVE-2023-41369?
CVE-2023-41369 allows an attacker to upload an XML file as an attachment in the Create Single Payment application of SAP S/4HANA, which can cause entity loops to slow down.
Are there any fixes or patches available for CVE-2023-41369?
The SAP Note 3369680 provides information regarding fixes or patches for CVE-2023-41369.