6.3

CVE-2024-33005

Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java), and SAP Content Server can impersonate other users and
may perform some unintended actions. This could lead to a low impact on
confidentiality and a high impact on the integrity and availability of the
applications.

Data is provided by the National Vulnerability Database (NVD)
SAPNetweaver Abap Versionkernel_7.22
SAPNetweaver Abap Versionkernel_7.53
SAPNetweaver Abap Versionkernel_7.54
SAPNetweaver Abap Versionkernel_7.77
SAPNetweaver Abap Versionkernel_7.85
SAPNetweaver Abap Versionkernel_7.89
SAPNetweaver Abap Versionkernel_7.93
SAPNetweaver Abap Versionkrnl64nuc_7.22
SAPNetweaver Abap Versionkrnl64nuc_7.22ext
SAPNetweaver Abap Versionkrnl64uc_7.22
SAPNetweaver Abap Versionkrnl64uc_7.22ext
SAPNetweaver Abap Versionkrnl64uc_7.53
SAPNetweaver Java Versionkernel_7.22
SAPNetweaver Java Versionkernel_7.53
SAPNetweaver Java Versionkernel_7.54
SAPNetweaver Java Versionkernel_7.77
SAPNetweaver Java Versionkernel_7.85
SAPNetweaver Java Versionkernel_7.89
SAPNetweaver Java Versionkernel_7.93
SAPNetweaver Java Versionkrnl64nuc_7.22
SAPNetweaver Java Versionkrnl64nuc_7.22ext
SAPNetweaver Java Versionkrnl64uc_7.22
SAPNetweaver Java Versionkrnl64uc_7.22ext
SAPNetweaver Java Versionkrnl64uc_7.53
SAPContent Server Versionkernel_7.22
SAPContent Server Versionkernel_7.53
SAPContent Server Versionkernel_7.54
SAPContent Server Versionkernel_7.77
SAPContent Server Versionkernel_7.85
SAPContent Server Versionkernel_7.89
SAPContent Server Versionkernel_7.93
SAPContent Server Versionkrnl64nuc_7.22
SAPContent Server Versionkrnl64nuc_7.22ext
SAPContent Server Versionkrnl64uc_7.22
SAPContent Server Versionkrnl64uc_7.22ext
SAPContent Server Versionkrnl64uc_7.53
SAPWeb Dispatcher Versionkernel_7.22
SAPWeb Dispatcher Versionkernel_7.53
SAPWeb Dispatcher Versionkernel_7.54
SAPWeb Dispatcher Versionkernel_7.77
SAPWeb Dispatcher Versionkernel_7.85
SAPWeb Dispatcher Versionkernel_7.89
SAPWeb Dispatcher Versionkernel_7.93
SAPWeb Dispatcher Versionkrnl64nuc_7.22
SAPWeb Dispatcher Versionkrnl64nuc_7.22ext
SAPWeb Dispatcher Versionkrnl64uc_7.22
SAPWeb Dispatcher Versionkrnl64uc_7.22ext
SAPWeb Dispatcher Versionkrnl64uc_7.53
SAPWeb Dispatcher Versionwebdisp_7.22_ext
SAPWeb Dispatcher Versionwebdisp_7.53
SAPWeb Dispatcher Versionwebdisp_7.54
SAPWeb Dispatcher Versionwebdisp_7.77
SAPWeb Dispatcher Versionwebdisp_7.85
SAPWeb Dispatcher Versionwebdisp_7.89
SAPWeb Dispatcher Versionwebdisp_7.93
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.208
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 0.8 5.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
cna@sap.com 6.3 0.8 5.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.