Executive brief
SAP ABAP Platform is a core component used by enterprises to run business-critical applications and data processing. An attacker can send a specially crafted request without authentication to extract non-sensitive data fragments from previously used memory locations, potentially disclosing configuration details or metadata that could aid in further attacks.
Technical details
This is an information disclosure vulnerability in SAP ABAP Platform affecting an internal component. The vulnerability allows unauthenticated attackers to craft specialized requests that leak non-sensitive data from memory previously allocated by the application. No authentication is required and the attack is network-accessible. While the confidentiality impact is assessed as low (limited, non-sensitive data), there is no impact to integrity or availability. Patches are expected to be available through SAP Security Patch Day channels.
Affected products
- SAP ABAP Platform
Timeline
- 2026-08-11: disclosed