CVE-2024-33005: Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33005?
CVE-2024-33005 has a low severity rating due to the limited impact on confidentiality.
How do I fix CVE-2024-33005?
To resolve CVE-2024-33005, apply the latest updates or patches provided by SAP for the affected systems.
Which SAP products are affected by CVE-2024-33005?
CVE-2024-33005 affects SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server.
What impact does CVE-2024-33005 have on users?
CVE-2024-33005 allows admin users to impersonate other users, which may lead to unintended actions.
Are there workarounds for CVE-2024-33005?
Currently, SAP recommends applying patches as the primary method to mitigate CVE-2024-33005.