CVE-2024-33007: SAP SE SAPUI5

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.

Affected products

  • SAP SE SAPUI5: version 754 only; version 755 only; version 756 only; version 757 only; version 758 only
  • SAP SE SAPUI5 Pdfviewer: version 754 only; version 755 only; version 756 only; version 757 only; version 758 only

Published 2024-05-14. Last modified 2026-06-17.