CVE-2024-33005
Last modified
CVE-2024-33005 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Abap | kernel_7.22 |
| Sap | Netweaver Abap | kernel_7.53 |
| Sap | Netweaver Abap | kernel_7.54 |
| Sap | Netweaver Abap | kernel_7.77 |
| Sap | Netweaver Abap | kernel_7.85 |
| Sap | Netweaver Abap | kernel_7.89 |
| Sap | Netweaver Abap | kernel_7.93 |
| Sap | Netweaver Abap | krnl64nuc_7.22 |
| Sap | Netweaver Abap | krnl64nuc_7.22ext |
| Sap | Netweaver Abap | krnl64uc_7.22 |
| Sap | Netweaver Abap | krnl64uc_7.22ext |
| Sap | Netweaver Abap | krnl64uc_7.53 |
| Sap | Netweaver Java | kernel_7.22 |
| Sap | Netweaver Java | kernel_7.53 |
| Sap | Netweaver Java | kernel_7.54 |
| Sap | Netweaver Java | kernel_7.77 |
| Sap | Netweaver Java | kernel_7.85 |
| Sap | Netweaver Java | kernel_7.89 |
| Sap | Netweaver Java | kernel_7.93 |
| Sap | Netweaver Java | krnl64nuc_7.22 |
| Sap | Netweaver Java | krnl64nuc_7.22ext |
| Sap | Netweaver Java | krnl64uc_7.22 |
| Sap | Netweaver Java | krnl64uc_7.22ext |
| Sap | Netweaver Java | krnl64uc_7.53 |
| Sap | Content Server | kernel_7.22 |
| Sap | Content Server | kernel_7.53 |
| Sap | Content Server | kernel_7.54 |
| Sap | Content Server | kernel_7.77 |
| Sap | Content Server | kernel_7.85 |
| Sap | Content Server | kernel_7.89 |
| Sap | Content Server | kernel_7.93 |
| Sap | Content Server | krnl64nuc_7.22 |
| Sap | Content Server | krnl64nuc_7.22ext |
| Sap | Content Server | krnl64uc_7.22 |
| Sap | Content Server | krnl64uc_7.22ext |
| Sap | Content Server | krnl64uc_7.53 |
| Sap | Web Dispatcher | kernel_7.22 |
| Sap | Web Dispatcher | kernel_7.53 |
| Sap | Web Dispatcher | kernel_7.54 |
| Sap | Web Dispatcher | kernel_7.77 |
| Sap | Web Dispatcher | kernel_7.85 |
| Sap | Web Dispatcher | kernel_7.89 |
| Sap | Web Dispatcher | kernel_7.93 |
| Sap | Web Dispatcher | krnl64nuc_7.22 |
| Sap | Web Dispatcher | krnl64nuc_7.22ext |
| Sap | Web Dispatcher | krnl64uc_7.22 |
| Sap | Web Dispatcher | krnl64uc_7.22ext |
| Sap | Web Dispatcher | krnl64uc_7.53 |
| Sap | Web Dispatcher | webdisp_7.22_ext |
| Sap | Web Dispatcher | webdisp_7.53 |
Showing 50 of 55 affected configurations. See NVD for the full list.
References
- https://me.sap.com/notes/3438085Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-33005?
How severe is CVE-2024-33005?
How do I fix CVE-2024-33005?
Are you affected by CVE-2024-33005?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
