9.8

CVE-2026-58240

Warnung
Medienbericht

Missing Authentication check in SAP NetWeaver (Message Server)

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt SAP NetWeaver (Message Server)
Default Statusunaffected
Version KERNEL 9.16
Status affected
Version 9.18
Status affected
Version 9.19
Status affected
Version 9.20
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.272
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
SAP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-308 Use of Single-factor Authentication

The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
14.09.2026 17:54
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
11.09.2026 12:12
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.09.2026 11:25
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 17:07
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3759472