Impact
An internal code path in SAP NetWeaver Application Server ABAP and ABAP Platform can be abused by an attacker with high system privileges to trigger an operating‑system command injection. The flaw allows the attacker to run arbitrary OS commands that can write data to the file system or shut down the SAP instance. The vulnerability does not compromise data confidentiality, has a low potential to alter system state, but can cause a loss of service because it can stop or destabilize the SAP environment.
Affected Systems
Products affected are SAP NetWeaver Application Server ABAP and the ABAP platform. Specific version details are not disclosed in the CVE data, so any instance of these products that has not applied the SAP security fix remains vulnerable.
Risk and Exploitability
The CVSS base score of 5.5 indicates a medium severity, and the lack of an EPSS score means no current estimation of exploitation probability is available. The vulnerability is not listed in the CISA KEV catalog. Inferred from the description, the exploitation path requires privileged access, so the risk is confined to internally empowered users. Successful exploitation could allow an attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.
OpenCVE Enrichment