CVE-2026-34265
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP NetWeaver and ABAP Platform | KRNL64NUC 7.22 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.22EXT | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | KRNL64UC 7.22 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.22EXT2 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.22EXT3 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.53 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.54 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.77 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.89 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 7.93 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 8.04 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 9.16 9.18 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 9.19 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | KERNEL 7.22 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 9.16 | affected |
| SAP_SE | SAP NetWeaver and ABAP Platform | 9.18 | affected |
Weaknesses
- CWE-787: CWE-787: Out-of-bounds Write
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.