Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.
Use CWE-862, Sap vendor hub and Netweaver Abap product page to widen CVE-2024-33005 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-38178, CVE-2022-22543 and CVE-2021-38181 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.