← Back to CVE List
Vulnerability Intelligence Report
Denial of service (DOS) in SAP NetWeaver and ABAP platform

CVE-2024-33001

SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial of Service vulnerability might be long response delays and service interruptions, thus degrading the service quality experienced by legitimate users causing high impact on availability of the application.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:0.41%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-400 ↗CWE-400: Uncontrolled Resource Consumption

Affected Products & Versions

Vendor Product Affected Versions
SAP_SE SAP NetWeaver and ABAP platform ST-PI 2008_1_700 (affected), 2008_1_710 (affected), 740 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.412%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2024-04-23T04:04:25
Published2024-06-11T02:05:00
Last Updated2024-08-02T02:27:53

LINK COPIED TO CLIPBOARD