Impact
This vulnerability is a CWE-497 (Improper Handling of Sensitive Information) flaw. SAP NetWeaver Application Server for ABAP writes sensitive session identifier information into a diagnostic trace when tracing is enabled by a privileged user. An attacker who can read the resulting trace data can acquire these identifiers and impersonate legitimate users while the identifiers remain valid, thereby creating a high confidentiality impact. The vulnerability does not affect integrity or availability.
Affected Systems
The affected products are SAP NetWeaver Application Server for ABAP, including all supported basis releases from 740 up to 758 and 795. These releases are listed in the CNA product list and the associated CPE strings.
Risk and Exploitability
The CVSS base score of 4.3 classifies the flaw as low severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires a privileged user to enable tracing and access the trace files, a condition that may be mitigated by restricting trace activation and read access. The risk is therefore limited but mitigable by applying the vendor’s fix.
OpenCVE Enrichment