Executive brief
SAP NetWeaver Application Server for ABAP contains a testing tool that can be misused to send unauthorized network requests. An attacker with basic user access could use this tool to probe internal systems or access sensitive data that is normally protected by the corporate firewall. While this does not crash the system, it could lead to the exposure of internal business information.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in an ABAP Report designed for testing purposes within SAP NetWeaver Application Server for ABAP. The report fails to properly validate or restrict the destination of HTTP requests, allowing an attacker with low-privileged network access to relay requests through the server. This can be used to interact with internal metadata services, internal network endpoints, or external systems. The vulnerability is tracked as CWE-918 and affects multiple SAP_BASIS versions. Successful exploitation has a low impact on confidentiality and integrity, with no impact on availability.
Affected products
- SAP NetWeaver Application Server for ABAP 740, 750, 752, 753, 754, 755, 756, 757, 758, 816, 918
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory