Executive brief
SAP NetWeaver Application Server for ABAP, a core component used to run business applications, contains a security flaw where certain log files are not properly protected. An authorized user with basic access could exploit this to view sensitive Database Analyzer log files they should not be able to see. While this does not allow an attacker to change data or crash the system, it could lead to the exposure of internal technical information.
Technical details
A missing authorization check (CWE-862) exists within a specific Remote Function Call (RFC) function module in SAP NetWeaver Application Server for ABAP (SAP_BASIS). An authenticated attacker with low-level user privileges can execute this module to bypass intended access restrictions and read Database Analyzer Log Files. This vulnerability allows for a limited escalation of privileges regarding data confidentiality, though it does not provide a mechanism to impact system integrity or availability. The issue affects multiple SAP_BASIS versions ranging from 700 to 816, and remediation is typically provided via SAP Security Notes (Note 3704740).
Affected products
- SAP NetWeaver Application Server ABAP (SAP_BASIS) 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816
Timeline
- 2026-03-10: disclosed: Initial disclosure by SAP SE
- 2026-03-10: advisory: NVD published the CVE entry