Executive brief
SAP NetWeaver Application Server ABAP, the core platform for many SAP business applications including S/4HANA, is vulnerable to an authentication bypass. An attacker with basic user access can manipulate security tokens to impersonate any other user, including administrators. This could lead to unauthorized access to sensitive business data, full system takeover, and disruption of operations.
Technical details
The SAML Service Provider in SAP NetWeaver AS ABAP (SAP_BASIS) is vulnerable to an XML Signature Wrapping (XSW) attack, specifically utilizing Signature/Object tags (XSW8). The vulnerability exists because the system verifies the cryptographic signature of a SAML assertion against one part of the XML document (the Object tag) while extracting the user identity attributes from a different, unverified part of the document. An attacker with 'normal' (low-privileged) authenticated access can obtain a valid signed SAML message and modify it to include a malicious assertion. By successfully wrapping the signature, the attacker can bypass integrity checks to impersonate any SAML-mapped user, including those with administrative privileges. The issue is tracked as CWE-347 and affects SAP_BASIS versions 700 through 918.
Affected products
- SAP SAP_BASIS (SAP NetWeaver AS ABAP) 700 - 918
Timeline
- 2025-10-23: other: Vulnerability discovered by SySS GmbH
- 2025-11-06: other: Vulnerability reported to SAP
- 2026-02-10: patched: SAP released security note 3697567
- 2026-02-10: advisory: Initial NVD publication
- 2026-06-08: disclosed: Full technical disclosure by SySS GmbH