Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java), and SAP Content Server can impersonate other users and
may perform some unintended actions. This could lead to a low impact on
confidentiality and a high impact on the integrity and availability of the
applications.
                
            References
                    | Link | Resource | 
|---|---|
| https://me.sap.com/notes/3438085 | Permissions Required | 
| https://url.sap/sapsecuritypatchday | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2024-08-13 04:15
Updated : 2024-09-12 14:39
NVD link : CVE-2024-33005
Mitre link : CVE-2024-33005
CVE.ORG link : CVE-2024-33005
JSON object : View
Products Affected
                sap
- content_server
- web_dispatcher
- netweaver_abap
- netweaver_java
CWE
                
                    
                        
                        CWE-862
                        
            Missing Authorization
