Description
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.
Published: 2026-07-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a CWE-497 (Improper Handling of Sensitive Information) flaw. SAP NetWeaver Application Server for ABAP writes sensitive session identifier information into a diagnostic trace when tracing is enabled by a privileged user. An attacker who can read the resulting trace data can acquire these identifiers and impersonate legitimate users while the identifiers remain valid, thereby creating a high confidentiality impact. The vulnerability does not affect integrity or availability.

Affected Systems

The affected products are SAP NetWeaver Application Server for ABAP, including all supported basis releases from 740 up to 758 and 795. These releases are listed in the CNA product list and the associated CPE strings.

Risk and Exploitability

The CVSS base score of 4.3 classifies the flaw as low severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires a privileged user to enable tracing and access the trace files, a condition that may be mitigated by restricting trace activation and read access. The risk is therefore limited but mitigable by applying the vendor’s fix.

Generated by OpenCVE AI on August 4, 2026 at 13:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest SAP security update referenced in SAP Note 3413033 to eliminate the diagnostic trace flaw.
  • Restrict the ability to enable diagnostic tracing to trusted administrators and enforce strict access controls on trace output locations.
  • Implement monitoring to detect unauthorized creation or read access to trace files, and auditing to log any attempts to exploit trace data.

Generated by OpenCVE AI on August 4, 2026 at 13:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.
Title Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
First Time appeared Sap Se
Sap Se sap Netweaver Application Server For Abap
Weaknesses CWE-497
CPEs cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_740:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_750:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_751:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_752:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_753:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_754:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_755:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_756:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_757:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_758:*:abap:*:*:*:*:*
cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_795:*:abap:*:*:*:*:*
Vendors & Products Sap Se
Sap Se sap Netweaver Application Server For Abap
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Sap Se Sap Netweaver Application Server For Abap
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-07-28T19:16:55.291Z

Reserved: 2026-06-29T19:35:04.186Z

Link: CVE-2026-58246

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T10:16:49.943

Modified: 2026-07-28T20:17:27.347

Link: CVE-2026-58246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere