Executive brief
SAP NetWeaver Application Server for ABAP and ABAP Platform is a core enterprise application server used to run mission-critical business processes. An unauthenticated attacker can send a specially crafted network packet to trick the server into reprocessing a previously buffered request from another user, potentially taking over their session. Successful exploitation could allow an attacker to impersonate legitimate users and access sensitive business data or modify critical information.
Technical details
This vulnerability is a request hijacking issue in SAP NetWeaver Application Server for ABAP that allows an unauthenticated attacker to trigger reprocessing of a previously buffered user request via a specially crafted network packet. The attack relies on narrow timing conditions to intercept and replay a victim's session state, resulting in unauthorized access to their authenticated session. The vulnerability has high impact on confidentiality and integrity (user data exposure and modification), with low impact on availability. The attack vector is network-based and requires no authentication, though successful exploitation depends on precise timing to coincide with a victim's active session. Patches are available via SAP Security Notes as part of the September 8, 2026 SAP Security Patch Day.
Affected products
- SAP NetWeaver Application Server for ABAP <UNKNOWN>
- SAP ABAP Platform <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Patches available via SAP Security Notes as part of SAP Security Patch Day