9.6
CVE-2024-33006
- EPSS 0.74%
- Veröffentlicht 14.05.2024 16:17:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellersap
≫
Produkt
netweaver
Default Statusunknown
Version
754
Status
affected
Herstellersap
≫
Produkt
netweaver
Default Statusunknown
Version
755
Status
affected
Herstellersap
≫
Produkt
netweaver
Default Statusunknown
Version
756
Status
affected
Herstellersap
≫
Produkt
netweaver
Default Statusunknown
Version
757
Status
affected
Herstellersap
≫
Produkt
netweaver
Default Statusunknown
Version
758
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.74% | 0.731 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.