CVE-2024-33006: File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Published May 14, 2024
·Updated
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.
Affected Software
2 affected components
SAP NetWeaver Application Server ABAP
SAP ABAP Platform
Event History
May 14, 2024
CVE Published
via MITRE·04:16 AM
Data Sourced
via MITRE·04:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33006?
CVE-2024-33006 is considered a critical vulnerability due to the ability of an unauthenticated attacker to upload malicious files.
2
How do I fix CVE-2024-33006?
To address CVE-2024-33006, it is essential to apply the latest security updates provided by SAP for affected products.
3
Which software is affected by CVE-2024-33006?
CVE-2024-33006 affects SAP NetWeaver Application Server ABAP and SAP ABAP Platform.
4
What are the potential consequences of CVE-2024-33006?
Exploitation of CVE-2024-33006 can lead to complete system compromise if the malicious file is accessed by a victim.
5
Is user authentication required to exploit CVE-2024-33006?
No, CVE-2024-33006 can be exploited by unauthenticated attackers, making it particularly dangerous.