Executive brief
SAP NetWeaver Application Server for ABAP is a foundational platform used by organizations to run business-critical SAP applications. A vulnerability exists that allows an administrative user to execute unauthorized operating system commands on the server. While this requires high-level access, an exploit could allow an attacker to disrupt business operations or modify system data without being detected by standard logging mechanisms.
Technical details
An OS command injection vulnerability (CWE-77) exists in SAP NetWeaver Application Server for ABAP and ABAP Platform. The flaw allows an authenticated attacker with high privileges (administrative access) to execute specially crafted shell commands on the underlying server via the network. A significant aspect of this vulnerability is the ability to bypass the system's logging mechanism, allowing for undetected execution of unintended commands. This can lead to a complete loss of integrity and availability for the affected application. SAP has released security notes (e.g., 3730019) to address this issue.
Affected products
- SAP NetWeaver Application Server for ABAP 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816
- SAP ABAP Platform
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory