Impact
SAP NetWeaver Application Server for ABAP allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, which can under narrow timing conditions hijack another user's session. The vulnerability is a memory corruption issue related to signed integer overflow (CWE‑191). Successful exploitation could result in high impact on confidentiality and integrity, but would cause only a low impact on application availability.
Affected Systems
The affected vendor is SAP, product is SAP NetWeaver Application Server for ABAP and ABAP Platform. No specific affected versions are provided in the data, so the vulnerability likely applies to all releases that contain the vulnerable code path.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote network attacker who can reach the application server and submit specially crafted packets. Exploitation requires precise timing, suggesting a moderate level of technical skill and a narrow window for success. Nonetheless, if achieved, it could lead to session hijacking and compromise the confidentiality and integrity of user data.
OpenCVE Enrichment