CVE-2024-33006: SAP NetWeaver

Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.

An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. 

Affected products

  • SAP NetWeaver: version 754 only; version 755 only; version 756 only; version 757 only; version 758 only
  • SAP SE SAP NetWeaver Application Server Abap And Abap Platform

Published 2024-05-14. Last modified 2026-06-17.