Impact
The SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component, resulting in a memory corruption that can expose limited, non‑sensitive data from previously used memory. The impact is confined to confidentiality, with no effect on integrity or availability. This weakness is identified as CWE‑908.
Affected Systems
Vendors and products affected are SAP SE’s SAP ABAP Platform. The CNA disclosure does not list specific product versions, so any instance of the platform that does not yet have the vendor’s latest fix may be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium‑to‑low severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker who can reach the internal component—typically over an internal network—can craft and send the malicious request. Because the incident results only in limited data leakage and no privilege escalation, the overall exploitation risk is moderate. No confirmed exploits have been reported as of the latest advisory.
OpenCVE Enrichment