CVE-2026-34265

Summary

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP NetWeaver and ABAP PlatformKRNL64NUC 7.22affected
SAP_SESAP NetWeaver and ABAP Platform7.22EXTaffected
SAP_SESAP NetWeaver and ABAP PlatformKRNL64UC 7.22affected
SAP_SESAP NetWeaver and ABAP Platform7.22EXT2affected
SAP_SESAP NetWeaver and ABAP Platform7.22EXT3affected
SAP_SESAP NetWeaver and ABAP Platform7.53affected
SAP_SESAP NetWeaver and ABAP Platform7.54affected
SAP_SESAP NetWeaver and ABAP Platform7.77affected
SAP_SESAP NetWeaver and ABAP Platform7.89affected
SAP_SESAP NetWeaver and ABAP Platform7.93affected
SAP_SESAP NetWeaver and ABAP Platform8.04affected
SAP_SESAP NetWeaver and ABAP Platform9.16 9.18affected
SAP_SESAP NetWeaver and ABAP Platform9.19affected
SAP_SESAP NetWeaver and ABAP PlatformKERNEL 7.22affected
SAP_SESAP NetWeaver and ABAP Platform9.16affected
SAP_SESAP NetWeaver and ABAP Platform9.18affected

Weaknesses

  • CWE-787: CWE-787: Out-of-bounds Write

References