Junglewise Threat Intelligence

CVE-2026-24310: SAP NetWeaver AS ABAP missing authorization check in ABAP function module

CVE-2026-24310 · Severity: low · CVSS 3.5 · Published 2026-03-10

Technologies: SAP NetWeaver Application Server for ABAP. Vendors: SAP.

Executive brief

A security vulnerability exists in SAP NetWeaver Application Server for ABAP, a core platform used for running business applications. An authorized user with low-level access could bypass security checks to view sensitive technical information about the system's database structure. While this does not allow the attacker to change data or crash the system, it provides technical details that could be used to plan further attacks.

Technical details

A missing authorization check (CWE-862) in SAP NetWeaver Application Server for ABAP (SAP_BASIS) allows an authenticated attacker to execute a specific ABAP function module. By invoking this module, the attacker can read sensitive information from the database catalog of the ABAP system. The vulnerability requires network access and basic user privileges. While the impact on confidentiality is rated as low and there is no impact on integrity or availability, the flaw allows unauthorized visibility into the system's underlying database schema. SAP has released security note 3694383 to address this issue.

Affected products

  • SAP NetWeaver Application Server for ABAP (SAP_BASIS) 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: SAP Security Patch Day March 2026

References

Related threats