Ad

CVE-2026-24309

MEDIUM CVSS 3.1: 6.4 EPSS 0.05%
Updated Mar 10, 2026
SAP
Parameter Value
CVSS 6.4 (MEDIUM)
Type CWE-862 (Missing Authorization)
Vendor SAP
Public PoC No

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerability has low impact on the application's integrity and availability, with no effect on confidentiality.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1