« Volver al listado

CVE-2024-33009

Estado: AplazadaMedia (4.2)—

SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-33009",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-33009",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-14T14:47:33.848687Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.2,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "SAP Global Label Management (GLM)",
          "versions": [
            {
              "status": "affected",
              "version": "605"
            },
            {
              "status": "affected",
              "version": "606"
            },
            {
              "status": "affected",
              "version": "616"
            },
            {
              "status": "affected",
              "version": "617"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:sap:global_label_management:605:*:*:*:*:*:*:*"
          ],
          "vendor": "sap",
          "product": "global_label_management",
          "versions": [
            {
              "status": "affected",
              "version": "605"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:sap:global_label_management:606:*:*:*:*:*:*:*"
          ],
          "vendor": "sap",
          "product": "global_label_management",
          "versions": [
            {
              "status": "affected",
              "version": "606"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:sap:global_label_management:616:*:*:*:*:*:*:*"
          ],
          "vendor": "sap",
          "product": "global_label_management",
          "versions": [
            {
              "status": "affected",
              "version": "616"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:sap:global_label_management:617:*:*:*:*:*:*:*"
          ],
          "vendor": "sap",
          "product": "global_label_management",
          "versions": [
            {
              "status": "affected",
              "version": "617"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-14T16:17:15.293",
  "references": [
    {
      "url": "https://me.sap.com/notes/1938764",
      "source": "cna@sap.com"
    },
    {
      "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
      "source": "cna@sap.com"
    },
    {
      "url": "https://me.sap.com/notes/1938764",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application."
    },
    {
      "lang": "es",
      "value": "SAP Global Label Management es vulnerable a la inyección SQL. Tras la explotación, el atacante puede utilizar entradas especialmente manipuladas para modificar los comandos de la base de datos, lo que da como resultado la recuperación de información adicional conservada por el sistema. Esto podría tener un bajo impacto en la confidencialidad y la integridad de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T07:30:52.260",
  "sourceIdentifier": "cna@sap.com"
}