CVE-2024-33007: Client-side script execution vulnerability in SAP UI5(PDFViewer)
PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33007?
The severity of CVE-2024-33007 is considered high due to the potential for executing harmful scripts embedded in PDF documents.
How do I fix CVE-2024-33007?
To fix CVE-2024-33007, ensure that your SAPUI5 version is updated to the latest security patch provided by SAP.
What are the potential impacts of CVE-2024-33007?
The potential impacts of CVE-2024-33007 include unauthorized execution of embedded JavaScript, leading to data breaches or malicious actions.
Which software is affected by CVE-2024-33007?
CVE-2024-33007 affects the SAPUI5 product, specifically the PDFViewer component.
Is there a workaround for CVE-2024-33007?
Currently, the recommendation is to update SAPUI5 to the latest version as the primary means to mitigate CVE-2024-33007.