The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3115598 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: sap
Published: 2023-04-11T02:58:49.648Z
Updated: 2023-04-11T20:17:39.130Z
Reserved: 2023-03-31T10:01:53.360Z
Link: CVE-2023-29109
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-11T03:15:07.927
Modified: 2023-04-18T15:31:41.727
Link: CVE-2023-29109
JSON object: View
Redhat Information
No data.
CWE