PT-2026-86951 · Sap Se · Sap Netweaver Application Server For Abap/Abap Platform

CVE-2026-66767

·

Publicado

2026-09-08

·

Atualizado

2026-09-08

CVSS v3.1

7.7

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.

Correção

Integer Underflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-66767

Produtos afetados

Sap Netweaver Application Server For Abap/Abap Platform