CVE-2024-33007

LOW

SAPUI5 PDFViewer - Embedded JavaScript Execution

Title source: manual
STIX 2.1

Description

PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.

References (2)

Core 2

Scores

CVSS v3 3.5
EPSS 0.0014
EPSS Percentile 33.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (5)
SAP_SE/SAPUI5 (PDFViewer) 754
SAP_SE/SAPUI5 (PDFViewer) 755
SAP_SE/SAPUI5 (PDFViewer) 756
SAP_SE/SAPUI5 (PDFViewer) 757
SAP_SE/SAPUI5 (PDFViewer) 758
Published May 14, 2024
Tracked Since Feb 18, 2026