Executive brief
SAP NetWeaver Business Client is an enterprise application used to access and manage business data in SAP systems. During startup, the application processes locally stored configuration data without adequate validation. An attacker with access to the user's system could replace this data with malicious content, leading to arbitrary code execution when the application launches, potentially compromising the user's credentials, data access, and system integrity.
Technical details
This is an insufficient input validation vulnerability in SAP NetWeaver Business Client's startup sequence. The vulnerable component processes locally stored data during application initialization without performing adequate integrity or authenticity checks. An attacker with local system privileges could craft malicious content to replace the legitimate data on disk. When the application is launched, this crafted input is processed, leading to arbitrary code execution within the user's security context. The attack vector is local (requires prior access to the system), but no authentication or user interaction is needed beyond the normal application launch. Patches are expected through SAP Security Notes on their regular patch schedule.
Affected products
- SAP NetWeaver Business Client
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: Published by NVD and SAP Security Patch Day