CVE-2024-32733 is a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform, stemming from insufficient input validation and output encoding. An unauthenticated attacker can inject malicious JavaScript into dynamically generated web pages. This allows for the access or modification of sensitive information, though it does not impact application availability, and is rated 6.1 MEDIUM on the CVSS scale. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows minimal community discussion or media coverage, indicating a low level of active exploitation or public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP NetWeaver Application Server ABAP And ABAP Platform | SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 795, SAP_BASIS 796CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.