CVE-2026-58246
Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period.Β This leads to high impact on confidentiality. Integrity and availability are not impacted.
| CWE | CWE-497 |
| Vendor | sap_se |
| Product | sap netweaver application server for abap |
| Published | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for sap_se sap netweaver application server for abap
Be the first to know when new medium vulnerabilities affecting sap_se sap netweaver application server for abap are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
SAP_SE / SAP NetWeaver Application Server for ABAP
SAP_BASIS 740 SAP_BASIS 750 SAP_BASIS 751 SAP_BASIS 752 SAP_BASIS 753 SAP_BASIS 754 SAP_BASIS 755 SAP_BASIS 756 SAP_BASIS 757 SAP_BASIS 758 SAP_BASIS 795