SAP Knowledge Base Article - Preview

3469586 - General recommendation on vulnerability CVE-2024-33006 for SAP KPRo

Symptom

Based on SAP Note 3448171 a recent known vulnerability was found, the CVE-2024-33006.
External information about the vulnerability can be found here CVE-2024-33006.
(https://www.cve.org/CVERecord?id=CVE-2024-33006)

Remark:
The SAP Note 3448171 does not deliver Code Correction. It is only an informative about the vulnerability.

This KBA is shall be continuously updated.

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."


Read more...

Environment

SAP NetWeaver all releases

Product

SAP NetWeaver all versions

Keywords

CVE-2024-33006,  CVE-2024,  33006, Bypass malware scanner, upload of malicious file, HTTP 401, Unauthorized, OAC0, Content Repository. KPro, Knowledge provider, No Signature, checkbox, enabled, SOMU_DB, File System, Content Repository, hacker attack, OAC0, CSADMIN , KBA , BC-SRV-KPR , Knowledge Provider , Known Error

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.