← Vulnerability feed

Vulnerability record · CVE-2024-33005 · published 13 August 2024

CVE-2024-33005: Sap netweaver abap missing authorization vulnerability

Sap · Netweaver Abap

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

6.3 CVSS 3.1 Medium EPSS 0.21% · top 90.2% CWE-862 · Missing authorization
6.3CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://me.sap.com/notes/3438085 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory

Track CVE-2024-33005 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-22536SAP NetWeaver and Web Dispatcher HTTP request smugglingSAP NetWeaver Application Server ABAP, NetWeaver Application Server Java, ABAP Platform, Content Server 7.53 and Web Dispatcher mishandle HTTP reques…KEVEPSS 98%analysed10.0CVE-2012-4341Sap netweaver abap memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and exe…EPSS 8.7%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%9.8CVE-2021-27610Sap netweaver abap improper authentication vulnerabilitySAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about…EPSS 1.3%9.4CVE-2023-33987Sap web dispatcher http request smuggling vulnerabilityAn unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBD…EPSS 0.69%9.4CVE-2023-35871Sap web dispatcher out-of-bounds write vulnerabilityThe SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KER…EPSS 0.60%9.4CVE-2021-38162Sap web dispatcher http request smuggling vulnerabilitySAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53…EPSS 2.7%8.8CVE-2021-38178Sap netweaver abap vulnerabilityThe software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2024-33005), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.