Impact
SAP NetWeaver Message Server fails to authenticate internal application server components during registration, allowing an unauthenticated attacker with network access to register an unauthorized component. This flaw can lead to unauthorized actions within the application environment, potentially compromising confidentiality, integrity, and availability of the system. The weakness is classified under CWE‑308, reflecting the absence of proper authentication checks.
Affected Systems
The vulnerability affects SAP NetWeaver Message Server as documented by SAP for the SAP_SE vendor. Systems running SAP NetWeaver (Message Server) that have not applied SAP note 3759472 or subsequent patch updates are susceptible. Vendors are advised to consult the referenced SAP service notes for affected product versions.
Risk and Exploitability
With a CVSS base score of 9.8, this flaw is considered critical. The EPSS score is currently unavailable, but the lack of authentication gives attackers a direct path to exploit the service by providing malicious component registration data. Based on the description, it is inferred that the attack requires network access to the Message Server, which may involve open or default ports. Although not listed in CISA KEV, the high severity and the fact that the target is an internal service suggest an elevated risk for with open network access or insufficient segmentation.
OpenCVE Enrichment