Vulnerability Intelligence Report
Denial of service (DOS) in SAP NetWeaver and ABAP platform
CVE-2024-33001
SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial of Service vulnerability might be long response delays and service interruptions, thus degrading the service quality experienced by legitimate users causing high impact on availability of the application.
No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:0.41%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-400 ↗CWE-400: Uncontrolled Resource Consumption
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP_SE | SAP NetWeaver and ABAP platform | ST-PI 2008_1_700 (affected), 2008_1_710 (affected), 740 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.412%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2024-04-23T04:04:25 |
| Published | 2024-06-11T02:05:00 |
| Last Updated | 2024-08-02T02:27:53 |
Community Chatter & Buzz