Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap Netweaver And Abap Platform |
|
| Vendors & Products |
Sap Se
Sap Se sap Netweaver And Abap Platform |
Tue, 08 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected. | |
| Title | Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2026-09-08T00:12:21.196Z
Updated: 2026-09-08T10:34:58.522Z
Reserved: 2026-08-20T05:15:36.823Z
Link: CVE-2026-76963
Updated: 2026-09-08T10:32:16.515Z
Status : Awaiting Analysis
Published: 2026-09-08T01:17:55.040
Modified: 2026-09-08T19:12:59.557
Link: CVE-2026-76963
No data.