Executive brief
SAP NetWeaver Application Server for ABAP is a foundational platform used to run business applications. A security flaw allows an authorized user to bypass permission checks and modify critical database configuration settings. This could lead to system performance issues or service interruptions, potentially impacting business operations.
Technical details
A missing authorization check (CWE-862) exists in specific ABAP function modules within SAP NetWeaver Application Server for ABAP. An authenticated attacker with low privileges can execute these modules over the network to read, insert, or modify entries in the system's database configuration tables. While the vulnerability does not allow for data theft (confidentiality), it enables unauthorized content changes that can degrade system performance or cause service interruptions. The issue affects multiple SAP_BASIS versions ranging from 700 to 816. SAP has released security note 3703856 to address this vulnerability.
Affected products
- SAP NetWeaver Application Server for ABAP (SAP_BASIS) 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816
Timeline
- 2026-03-10: disclosed: Initial publication by SAP and NVD
- 2026-03-10: advisory: SAP Security Note 3703856 released