Vulnerabilities > CVE-2024-33005 - Missing Authorization vulnerability in SAP products

047910
CVSS 6.3 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
sap
CWE-862

Summary

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

Vulnerable Configurations

Part Description Count
Application
Sap
55

Common Weakness Enumeration (CWE)