CVE-2024-33002: Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
Published May 14, 2024
·Updated
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
Affected Software
1 affected component
SAP S/4HANA
Event History
May 14, 2024
CVE Published
via MITRE·03:49 AM
Data Sourced
via MITRE·03:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33002?
CVE-2024-33002 has a low impact on the Confidentiality and Integrity of the application.
2
How do I fix CVE-2024-33002?
To fix CVE-2024-33002, ensure that user-controlled inputs are properly encoded in the Document Service handler.
3
What software is affected by CVE-2024-33002?
CVE-2024-33002 affects SAP S/4HANA, specifically the Document Service handler within the Data Provisioning Service.
4
What type of vulnerability is CVE-2024-33002?
CVE-2024-33002 is a Cross-Site Scripting (XSS) vulnerability.
5
Is CVE-2024-33002 still relevant for current SAP systems?
Yes, CVE-2024-33002 remains relevant for current installations of SAP S/4HANA until properly patched.