Unknown
CVE-2024-33005
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2024-33005
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java), and SAP Content Server can impersonate other users and
may perform some unintended actions. This could lead to a low impact on
confidentiality and a high impact on the integrity and availability of the
applications.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- sap
Products
- content server kernel 7.22,
- content server kernel 7.53,
- content server kernel 7.54,
- content server kernel 7.77,
- content server kernel 7.85,
- content server kernel 7.89,
- content server kernel 7.93,
- content server krnl64nuc 7.22,
- content server krnl64nuc 7.22ext,
- content server krnl64uc 7.22,
- content server krnl64uc 7.22ext,
- content server krnl64uc 7.53,
- netweaver abap kernel 7.22,
- netweaver abap kernel 7.53,
- netweaver abap kernel 7.54,
- netweaver abap kernel 7.77,
- netweaver abap kernel 7.85,
- netweaver abap kernel 7.89,
- netweaver abap kernel 7.93,
- netweaver abap krnl64nuc 7.22,
- netweaver abap krnl64nuc 7.22ext,
- netweaver abap krnl64uc 7.22,
- netweaver abap krnl64uc 7.22ext,
- netweaver abap krnl64uc 7.53,
- netweaver java kernel 7.22,
- netweaver java kernel 7.53,
- netweaver java kernel 7.54,
- netweaver java kernel 7.77,
- netweaver java kernel 7.85,
- netweaver java kernel 7.89,
- netweaver java kernel 7.93,
- netweaver java krnl64nuc 7.22,
- netweaver java krnl64nuc 7.22ext,
- netweaver java krnl64uc 7.22,
- netweaver java krnl64uc 7.22ext,
- netweaver java krnl64uc 7.53,
- web dispatcher kernel 7.22,
- web dispatcher kernel 7.53,
- web dispatcher kernel 7.54,
- web dispatcher kernel 7.77,
- web dispatcher kernel 7.85,
- web dispatcher kernel 7.89,
- web dispatcher kernel 7.93,
- web dispatcher krnl64nuc 7.22,
- web dispatcher krnl64nuc 7.22ext,
- web dispatcher krnl64uc 7.22,
- web dispatcher krnl64uc 7.22ext,
- web dispatcher krnl64uc 7.53,
- web dispatcher webdisp 7.22 ext,
- web dispatcher webdisp 7.53,
- web dispatcher webdisp 7.54,
- web dispatcher webdisp 7.77,
- web dispatcher webdisp 7.85,
- web dispatcher webdisp 7.89,
- web dispatcher webdisp 7.93
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: