CVE-2024-42374
BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve information from the SAP ADS system and exhaust the number of XMLForm service which makes the SAP ADS rendering (PDF creation) unavailable. This affects the confidentiality and availability of the application.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- EPSS probability
- 0.54%
- CWE
- CWE-91
- Published
- 2024-08-13
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP BEx Web Java Runtime Export Web Service
- SAP_SE SAP BEx Web Java Runtime Export Web Service
- SAP_SE SAP BEx Web Java Runtime Export Web Service
- SAP_SE SAP BEx Web Java Runtime Export Web Service
- SAP_SE SAP BEx Web Java Runtime Export Web Service
Weakness type
Related vulnerabilities
- CVE-2026-2310 — IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data
- CVE-2026-83618 — xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
- CVE-2026-83617 — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
- CVE-2026-83616 — xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
- CVE-2026-83609 — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
- CVE-2026-83608 — xmldom: DocType `name` Injection Bypasses requireWellFormed
- CVE-2026-83607 — xmldom: Element name injection via createElement() bypasses requireWellFormed
- CVE-2026-83605 — xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed