Executive brief
SAP Gateway, a component used to connect devices and platforms to SAP systems, is vulnerable to a flaw where attackers can manipulate error messages. By injecting specific content, an attacker can force the system to reveal internal technical details, such as how it processes web addresses and internal search patterns. While this does not allow for data deletion or system takeover, it provides reconnaissance information that could be used to plan more sophisticated attacks.
Technical details
A vulnerability in SAP Gateway (CWE-497) allows an authenticated attacker with low privileges to inject content into system error messages. This injection can trigger the disclosure of sensitive technical information, including request artefacts such as regex patterns and the underlying URI parsing logic used by the gateway. The attack is conducted over the network and requires no user interaction. While the impact on confidentiality is rated as low and there is no impact on integrity or availability, the disclosed information aids in mapping the internal architecture of the SAP environment. SAP has released security note 3433366 to address this issue.
Affected products
- SAP Gateway
Timeline
- 2026-05-26: disclosed: Initial publication of the CVE record
- 2026-05-26: advisory: SAP released security note 3433366