8.1
CVE-2026-0506
- EPSS 0.04%
- Veröffentlicht 13.01.2026 01:14:33
- Zuletzt bearbeitet 22.01.2026 18:48:00
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Version700 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version701 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version702 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version731 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version740 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version750 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version751 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version752 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version753 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version754 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version755 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version756 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version757 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version758 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version816 SwEditionsap_basis
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.131 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.