Executive brief
SAP NetWeaver Application Server ABAP is a foundational platform for running SAP business applications. A security flaw allows attackers to create deceptive links that redirect users from a legitimate SAP domain to a malicious website. This can be used in phishing campaigns to steal user credentials or distribute malware by tricking employees into believing they are still on a trusted corporate page.
Technical details
An open redirect vulnerability (CWE-601) exists in SAP NetWeaver Application Server ABAP due to insufficient validation of user-supplied input used in redirection targets. An unauthenticated remote attacker can exploit this by persuading a victim to click a specially crafted URL. Successful exploitation allows the attacker to redirect the victim to an untrusted external site, which can facilitate phishing or cross-site scripting (XSS) attacks. The vulnerability affects multiple SAP_BASIS versions ranging from 700 to 816. SAP has released security notes (e.g., 3692004) to address this issue.
Affected products
- SAP SE NetWeaver Application Server ABAP 700, 701, 702, 731, 740, 750, 752, 753, 754, 755, 756, 757, 758, 816 (SAP_BASIS)
Timeline
- 2026-04-14: advisory: Initial publication by SAP and NVD