Executive brief
SAP NetWeaver Application Server for ABAP, a core component for running SAP business applications, contains a vulnerability where sensitive session identifiers are recorded in diagnostic logs. If a privileged user activates diagnostic tracing, these identifiers are exposed, potentially allowing an attacker with access to those logs to impersonate legitimate users. This could lead to unauthorized access to business data, though it does not directly allow the attacker to modify data or disrupt system availability.
Technical details
The vulnerability is classified as an exposure of sensitive information (CWE-497) within the diagnostic tracing component of SAP NetWeaver AS ABAP. When a privileged user enables diagnostic tracing, the system inadvertently records active session identifiers into the trace files. An attacker who gains access to these trace logs—requiring high privileges and adjacent network access—can extract these identifiers to hijack active user sessions. The exploitability is limited by the validity period of the session identifiers and requires the trace to be actively running. SAP has released security notes (3413033) to address this behavior.
Affected products
- SAP SE NetWeaver Application Server for ABAP and ABAP Platform SAP_BASIS 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 795
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory