CVE-2024-33005: SAP Content Server

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

Affected products

  • SAP Content Server: version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; version kernel_7.89 only; …
  • SAP NetWeaver Abap: version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; version kernel_7.89 only; …
  • SAP NetWeaver Java: version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; version kernel_7.89 only; …
  • SAP Web Dispatcher: version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; version kernel_7.89 only; …

Published 2024-08-13. Last modified 2026-06-17.