Executive brief
SAP Application Server ABAP contains a security flaw where it fails to properly verify user permissions during certain operations. An authenticated user could exploit this to run report generation commands that overwrite data belonging to other users, potentially leading to an unauthorized increase in their own access levels. This could compromise the integrity of business data and disrupt normal operations, though it does not directly expose sensitive information.
Technical details
A missing authorization check (CWE-862) exists within the SAP Application Server ABAP. An authenticated attacker with low privileges can exploit this vulnerability over the network to execute report generation commands. This action allows the attacker to overwrite information belonging to other users, leading to a vertical privilege escalation. The exploit has a high impact on system integrity and a low impact on availability, while confidentiality remains unaffected. SAP has addressed this in SAP Note 3735546.
Affected products
- SAP Application Server ABAP
Timeline
- 2026-06-09: disclosed: Initial publication date
- 2026-06-09: advisory: SAP Security Patch Day release