Impact
The SAP Fiori App for Intercompany Balance Reconciliation contains an unrestricted file upload flaw that permits a user with high privileges to submit any file type, including executable scripts, because the application performs no file format validation. The report notes that any consequences for confidentiality, integrity, or availability are low, suggesting the vulnerability is limited to the application layer. The weakness is a classic instance of CWE-434, which deals with the failure to restrict inadequate or unsafe file uploads.
Affected Systems
This issue resides in SAP’s Fiori App (Intercompany Balance Reconciliation). No specific version range is supplied, so the vulnerability applies to all current installations of the application that have not been patched according to SAP security note 3565506.
Risk and Exploitability
The CVSS score of 6.6 indicates a moderate severity, and the EPSS score of less than 1% signals that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need an account with high privileges to take advantage of the unsigned file upload; based on the description, it is inferred that if the uploaded file were later processed by the system (for example, parsed or executed), it could lead to unintended behavior or code execution. However, no direct evidence of such an outcome is supplied in the description.
OpenCVE Enrichment