6.1

CVE-2026-34257

Open Redirect vulnerability in SAP NetWeaver Application Server ABAP

Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
Produkt SAP NetWeaver Application Server ABAP
Default Statusunaffected
Version SAP_BASIS 700
Status affected
Version SAP_BASIS 701
Status affected
Version SAP_BASIS 702
Status affected
Version SAP_BASIS 731
Status affected
Version SAP_BASIS 740
Status affected
Version SAP_BASIS 750
Status affected
Version SAP_BASIS 752
Status affected
Version SAP_BASIS 753
Status affected
Version SAP_BASIS 754
Status affected
Version SAP_BASIS 755
Status affected
Version SAP_BASIS 756
Status affected
Version SAP_BASIS 757
Status affected
Version SAP_BASIS 758
Status affected
Version SAP_BASIS 816
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.176
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@sap.com 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.