Skip to content
SAPCVE-2026-58246

SAP NetWeaver Application Server for ABAP: system information exposure

Medium4.3CVE-2026-58246 · Published Jul 28, 2026

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP NetWeaver Application Server for ABAP
Product
<= SAP_BASIS 740No fix yet
<= SAP_BASIS 750No fix yet
<= SAP_BASIS 751No fix yet
<= SAP_BASIS 752No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-497

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...
Critical9.1Jul 14
SAP @ui5/webcomponents-base: clickjacking
Medium6.1Jul 14
SAP CRM (WebClient UI): attacker could inject
Medium4.1Jul 14
SAP S/4HANA Project Management (PPM-PRO): SQL injection
Medium5.5Jul 14
SAP S/4 HANA (Create Single Payment): missing authorization
Medium4.3Jul 14
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.