Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3692004 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-14 01:16
Updated : 2026-06-17 10:38
NVD link : CVE-2026-34257
Mitre link : CVE-2026-34257
CVE.ORG link : CVE-2026-34257
JSON object : View
Products Affected
sap
- netweaver_application_server_abap
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
