CVE-2024-34692: [CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now
Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker can cause limited impact on confidentiality and Integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34692?
CVE-2024-34692 is classified as a high-severity vulnerability due to the ability of an authenticated attacker to upload arbitrary files.
How do I fix CVE-2024-34692?
To fix CVE-2024-34692, ensure that file type verification and content validation is properly implemented in SAP Enable Now configurations.
What are the potential impacts of CVE-2024-34692?
The potential impacts of CVE-2024-34692 include unauthorized file uploads, which could lead to malware distribution and execution on user systems.
Who is affected by CVE-2024-34692?
CVE-2024-34692 affects all users of SAP Enable Now that allow file uploads without proper verification.
Is there a workaround for CVE-2024-34692?
A temporary workaround for CVE-2024-34692 involves strictly controlling user permissions for file uploads and monitoring uploaded files closely.