THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-33009

SQL injection vulnerability in SAP Global Label Management (GLM)

Reserved:2024-04-23
Published:2024-05-14
Updated:2024-05-14

Description

SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.



MEDIUM: 4.2CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-89: Improper Neutralization of Special Elements used in an SQL Command

Product status

Default status
unaffected

605
affected

606
affected

616
affected

617
affected

References

https://me.sap.com/notes/1938764

https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html

cve.org CVE-2024-33009

nvd.nist.gov CVE-2024-33009

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-33009