Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
High
Attack Vector
Local
0

CVE-2024-33005

Disclosure Date: August 13, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java), and SAP Content Server can impersonate other users and
may perform some unintended actions. This could lead to a low impact on
confidentiality and a high impact on the integrity and availability of the
applications.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.3 Medium
Impact Score:
5.5
Exploitability Score:
0.8
Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
Low
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • sap

Products

  • content server kernel 7.22,
  • content server kernel 7.53,
  • content server kernel 7.54,
  • content server kernel 7.77,
  • content server kernel 7.85,
  • content server kernel 7.89,
  • content server kernel 7.93,
  • content server krnl64nuc 7.22,
  • content server krnl64nuc 7.22ext,
  • content server krnl64uc 7.22,
  • content server krnl64uc 7.22ext,
  • content server krnl64uc 7.53,
  • netweaver abap kernel 7.22,
  • netweaver abap kernel 7.53,
  • netweaver abap kernel 7.54,
  • netweaver abap kernel 7.77,
  • netweaver abap kernel 7.85,
  • netweaver abap kernel 7.89,
  • netweaver abap kernel 7.93,
  • netweaver abap krnl64nuc 7.22,
  • netweaver abap krnl64nuc 7.22ext,
  • netweaver abap krnl64uc 7.22,
  • netweaver abap krnl64uc 7.22ext,
  • netweaver abap krnl64uc 7.53,
  • netweaver java kernel 7.22,
  • netweaver java kernel 7.53,
  • netweaver java kernel 7.54,
  • netweaver java kernel 7.77,
  • netweaver java kernel 7.85,
  • netweaver java kernel 7.89,
  • netweaver java kernel 7.93,
  • netweaver java krnl64nuc 7.22,
  • netweaver java krnl64nuc 7.22ext,
  • netweaver java krnl64uc 7.22,
  • netweaver java krnl64uc 7.22ext,
  • netweaver java krnl64uc 7.53,
  • web dispatcher kernel 7.22,
  • web dispatcher kernel 7.53,
  • web dispatcher kernel 7.54,
  • web dispatcher kernel 7.77,
  • web dispatcher kernel 7.85,
  • web dispatcher kernel 7.89,
  • web dispatcher kernel 7.93,
  • web dispatcher krnl64nuc 7.22,
  • web dispatcher krnl64nuc 7.22ext,
  • web dispatcher krnl64uc 7.22,
  • web dispatcher krnl64uc 7.22ext,
  • web dispatcher krnl64uc 7.53,
  • web dispatcher webdisp 7.22 ext,
  • web dispatcher webdisp 7.53,
  • web dispatcher webdisp 7.54,
  • web dispatcher webdisp 7.77,
  • web dispatcher webdisp 7.85,
  • web dispatcher webdisp 7.89,
  • web dispatcher webdisp 7.93

Additional Info

Technical Analysis