Executive brief
A code injection vulnerability exists in SAP Application Server ABAP, a core component used for running business applications. An authenticated user could send malicious data that, when processed, executes code for other users subscribed to the same communication channel. While this could allow unauthorized changes to data, it does not currently appear to allow the theft of sensitive information or cause system outages.
Technical details
A code injection vulnerability (CWE-94) exists in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform. An authenticated attacker with low privileges can send specially crafted inputs to the application. If these inputs are processed, they can be delivered to other users subscribed to the specific communication channel, leading to the execution of arbitrary code in their context. The impact is limited to integrity (low), with no reported impact on confidentiality or availability. SAP has released security note 3735359 to address this issue.
Affected products
- SAP SE SAP NetWeaver Application Server ABAP
- SAP SE ABAP Platform
Timeline
- 2026-05-12: advisory: SAP Security Patch Day release
- 2026-05-12: disclosed: CVE published to NVD