Impact
SAP NetWeaver Application Server ABAP contains a memory corruption flaw caused by logical errors in the DIAG protocol parsing. This vulnerability, classified as CWE-787, could allow an attacker to corrupt memory, potentially resulting in the disclosure of sensitive system information or a system crash. Consequently, the confidentiality, integrity, and availability of the application could be severely impacted.
Affected Systems
The flaw affects SAP NetWeaver and ABAP Platform servers provided by SAP SE. No specific product versions are enumerated in the data; therefore, any installed instance of the listed products may be at risk until the patch is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical level of risk. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack requires unauthenticated access to the DIAG protocol, implying that a threat actor with network reachability to the application server can exploit the flaw. No official workaround is supplied; remediation relies on applying SAP’s security patch (see SAP Note 3714806) or disabling the DIAG protocol if feasible.
OpenCVE Enrichment