Description
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component, resulting in a memory corruption that can expose limited, non‑sensitive data from previously used memory. The impact is confined to confidentiality, with no effect on integrity or availability. This weakness is identified as CWE‑908.

Affected Systems

Vendors and products affected are SAP SE’s SAP ABAP Platform. The CNA disclosure does not list specific product versions, so any instance of the platform that does not yet have the vendor’s latest fix may be vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium‑to‑low severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker who can reach the internal component—typically over an internal network—can craft and send the malicious request. Because the incident results only in limited data leakage and no privilege escalation, the overall exploitation risk is moderate. No confirmed exploits have been reported as of the latest advisory.

Generated by OpenCVE AI on August 11, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for SAP ABAP Platform.
  • Restrict network access to the internal component, ensuring only authorized hosts can send requests.
  • Enable memory protection mitigations such as address space layout randomization and stack canaries on the application servers.
  • Monitor logs for unusual or malformed requests against the internal component that might indicate exploitation attempts.

Generated by OpenCVE AI on August 11, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.
Title Memory Corruption vulnerability in SAP ABAP Platform
Weaknesses CWE-908
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:17:06.514Z

Reserved: 2026-06-29T19:35:04.186Z

Link: CVE-2026-58247

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource