Description
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
Published: 2026-08-11
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP NetWeaver Application Server ABAP contains a memory corruption flaw caused by logical errors in the DIAG protocol parsing. This vulnerability, classified as CWE-787, could allow an attacker to corrupt memory, potentially resulting in the disclosure of sensitive system information or a system crash. Consequently, the confidentiality, integrity, and availability of the application could be severely impacted.

Affected Systems

The flaw affects SAP NetWeaver and ABAP Platform servers provided by SAP SE. No specific product versions are enumerated in the data; therefore, any installed instance of the listed products may be at risk until the patch is applied.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical level of risk. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack requires unauthenticated access to the DIAG protocol, implying that a threat actor with network reachability to the application server can exploit the flaw. No official workaround is supplied; remediation relies on applying SAP’s security patch (see SAP Note 3714806) or disabling the DIAG protocol if feasible.

Generated by OpenCVE AI on August 11, 2026 at 01:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch referenced in SAP Note 3714806 to update the Application Server ABAP to a patched build.
  • Disable or restrict access to the DIAG protocol on the affected servers to limit the attack surface.
  • Monitor system logs for abnormal DIAG traffic that may indicate exploitation attempts.

Generated by OpenCVE AI on August 11, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Netweaver And Abap Platform
Vendors & Products Sap Se
Sap Se sap Netweaver And Abap Platform

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
Title Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Sap Se Sap Netweaver And Abap Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:10:52.687Z

Reserved: 2026-03-26T19:02:45.983Z

Link: CVE-2026-34265

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:45:06Z

Weaknesses