← Vulnerability feed

Vulnerability record · CVE-2023-29109 · published 11 April 2023

CVE-2023-29109: Sap abap platform csv injection vulnerability

Sap · Abap Platform

The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application.

4.6 CVSS 3.1 Medium EPSS 0.32% · top 77.1% CWE-1236 · CSV injection
4.6CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29109 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44231Sap abap platform code injection vulnerabilityInternally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…EPSS 1.3%9.1CVE-2024-21737Sap application interface framework code injection vulnerabilityIn SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers…EPSS 0.61%9.1CVE-2021-33701Sap dmis sql injection vulnerabilityDMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 202…EPSS 2.1%8.8CVE-2022-41264Sap basis code injection vulnerabilityDue to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allow…EPSS 0.89%8.8CVE-2020-6296Sap abap platform vulnerabilitySAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject co…EPSS 1.3%8.8CVE-2018-2484Sapscore missing authorization vulnerabilitySAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.0…EPSS 1.4%7.3CVE-2023-35870Sap s4core incorrect permission assignment vulnerabilityWhen creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could interce…EPSS 0.38%7.2CVE-2024-22131Sap abap platform code injection vulnerabilityIn SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2023-29109), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.