me.sap.com
https://me.sap.com/notes/3448171 CVE-2024-33006
CRITICAL
File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Record summary
CVE-2024-33006 has a selected CVSS score of 9.6 (critical).
Description
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SAP NetWeaver Application Server ABAP and ABAP PlatformBrowse SAP_SE / SAP NetWeaver Application Server ABAP and ABAP PlatformDefault status: unaffected | CVE List | SAP_BASIS 700 | affected |
| SAP_BASIS 701 | affected | ||
| SAP_BASIS 702 | affected | ||
| SAP_BASIS 731 | affected | ||
| SAP_BASIS 740 | affected | ||
| SAP_BASIS 750 | affected | ||
| SAP_BASIS 751 | affected | ||
| SAP_BASIS 752 | affected | ||
| SAP_BASIS 753 | affected | ||
| SAP_BASIS 754 | affected | ||
| SAP_BASIS 755 | affected | ||
| SAP_BASIS 756 | affected | ||
| Showing 12 of 14 version ranges | |||
netweaverBrowse sap / netweaverDefault status: unknown | CVE List | 754 | affected |
| 755 | affected | ||
| 756 | affected | ||
| 757 | affected | ||
| 758 | affected | ||
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33006 support.sap.com
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html