CVE-2024-33005

MEDIUM

SAP NetWeaver ABAP and Java, Content Server - Missing Authorization

Title source: llm
STIX 2.1

Description

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3438085

Scores

CVSS v3 6.3
EPSS 0.0009
EPSS Percentile 25.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (50)
sap/content_server kernel_7.22
sap/content_server kernel_7.53
sap/content_server kernel_7.54
sap/content_server kernel_7.77
sap/content_server kernel_7.85
sap/content_server kernel_7.89
sap/content_server kernel_7.93
sap/content_server krnl64nuc_7.22
sap/content_server krnl64nuc_7.22ext
sap/content_server krnl64uc_7.22
... and 40 more
Published Aug 13, 2024
Tracked Since Feb 18, 2026