Description
SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the affected component. This causes a temporary service interruption and automatic restart, resulting in low impact on availability but no impact on confidentiality and integrity.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SAPSPrint Service has a memory corruption bug that allows an unauthenticated attacker to send crafted requests that overflow a buffer. The overflow triggers a crash and an automatic restart, causing a temporary pause in service availability. The vulnerability does not compromise confidentiality or integrity, and it is classified under CWE‑121. The impact is mainly a short‑lived denial of service.

Affected Systems

The flaw affects SAP's SAPSPrint Service. No specific version information is listed in the CNA data. Organizations using this service should verify whether their deployments are impacted by checking the referenced SAP Note or contacting SAP support.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. Because the EPSS score is unavailable and the issue is not in a CISA KEV catalog, the likelihood of widespread exploitation is unclear. The attack vector is inferred to be remote, as the attacker sends traffic over the network, and authentication is not required. While the service interruption is brief, repeated exploitation could degrade user experience.

Generated by OpenCVE AI on August 11, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP patch detailed in SAP Note 3725940 to eliminate the buffer overflow in SAPSPrint Service.
  • Restrict network access to the SAPSPrint Service so that only authorized hosts can reach it, reducing the attack surface for unauthenticated traffic.
  • Enable logging and monitoring for the SAPSPrint Service, and watch for abnormal restarts that could indicate exploitation attempts.

Generated by OpenCVE AI on August 11, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the affected component. This causes a temporary service interruption and automatic restart, resulting in low impact on availability but no impact on confidentiality and integrity.
Title Memory Corruption vulnerability in SAPSPrint Service
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:11:07.025Z

Reserved: 2026-04-09T17:29:44.663Z

Link: CVE-2026-40130

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:45:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow