CVE-2026-58246
4.3
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Summary
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 740 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 750 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 751 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 752 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 753 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 754 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 755 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 756 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 757 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 758 | affected |
| SAP_SE | SAP NetWeaver Application Server for ABAP | SAP_BASIS 795 | affected |
Weaknesses
- CWE-497: CWE-497 Exposure of sensitive system information to an unauthorized control sphere
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.