Executive brief
SAP NetWeaver Application Server ABAP and the ABAP Platform are core components used to run business applications and manage enterprise data. A vulnerability in how these systems verify digital signatures allows a logged-in user to modify identity information and gain unauthorized access to sensitive data. This could lead to a significant breach of confidentiality and disrupt critical business operations.
Technical details
A signature verification vulnerability (CWE-347) exists in SAP NetWeaver AS ABAP and ABAP Platform. An authenticated attacker with standard user privileges can intercept or obtain a validly signed XML message and subsequently submit modified versions of that document to the system's verifier. Because the system fails to properly validate the integrity of the modified signed XML, it may accept tampered identity or authorization information. This allows for privilege escalation and unauthorized access to sensitive data across the application. The vulnerability is reachable over the network and has a high impact on confidentiality, integrity, and availability.
Affected products
- SAP NetWeaver Application Server ABAP
- SAP ABAP Platform
Timeline
- 2026-06-09: advisory: Published as part of SAP Security Patch Day June 2026