3.1
CVE-2026-24320
- EPSS 0.01%
- Veröffentlicht 10.02.2026 03:03:42
- Zuletzt bearbeitet 17.02.2026 15:27:30
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or availability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver As Abap Kernel Version7.22
SAP ≫ Netweaver As Abap Kernel Version7.54
SAP ≫ Netweaver As Abap Kernel Version7.77
SAP ≫ Netweaver As Abap Kernel Version7.89
SAP ≫ Netweaver As Abap Kernel Version7.93
SAP ≫ Netweaver As Abap Kernel Version9.16
SAP ≫ Netweaver As Abap Kernel Version9.17
SAP ≫ Netweaver As Abap Kernel Version9.18
SAP ≫ Netweaver As Abap Krnl64nuc Version7.22
SAP ≫ Netweaver As Abap Krnl64nuc Version7.22ext
SAP ≫ Netweaver As Abap Krnl64uc Version7.22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.017 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| cna@sap.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.