CVE-2024-33007: SAP SE SAPUI5
Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.
PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.
Affected products
- SAP SE SAPUI5: version 754 only; version 755 only; version 756 only; version 757 only; version 758 only
- SAP SE SAPUI5 Pdfviewer: version 754 only; version 755 only; version 756 only; version 757 only; version 758 only
Published 2024-05-14. Last modified 2026-06-17.