Back to overview

CVE-2026-58246

MEDIUM
4.3
CVSS 3.1
Description
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

Metadata

CVE ID
CVE-2026-58246
State
PUBLISHED
Assigner
sap
Reserved
2026-06-29 19:35 UTC
Published
2026-07-28 09:51 UTC
Last updated
2026-07-28 19:16 UTC
Primary CWE
CWE-497
CWE-497 Exposure of sensitive system information to an unaut…
Vendor / Product
SAP_SE / SAP NetWeaver Application Server for ABAP
Sources
cve.org  ·  NVD

Severity & Metrics

4.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
SAP_SE SAP NetWeaver Application Server for ABAP ABAP SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752 …
Weakness (CWE)
CWESourceDescription
CWE-497 cna CWE-497 Exposure of sensitive system information to an unauthorized control sphere
CVSS scores (1)
ScoreSeverityVersionSourceVector
4.3 MEDIUM 3.1 cna CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Back to overview