6.1
CVE-2026-34257
- EPSS 0.16%
- Veröffentlicht 14.04.2026 00:08:39
- Zuletzt bearbeitet 03.06.2026 19:06:45
- Erkennungen
Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Version 700 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 701 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 702 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 731 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 740 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 750 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 752 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 753 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 754 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 755 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 756 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 757 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 758 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 816 SwEdition sap_basis
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.049 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| SAP | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3692004