SAP NetWeaver Application Server for ABAP Missing Authorization Check Vulnerability Allowing Unauthorized Database Modifications

Vulnerability

A vulnerability exists in SAP NetWeaver Application Server for ABAP due to a missing authorization check. This flaw allows authenticated attackers to execute specific ABAP function modules that can read, modify, or insert entries into the database configuration table of the ABAP system. Such unauthorized changes could degrade system performance or cause disruptions. While the vulnerability has a low impact on the application's integrity and availability, it does not affect confidentiality.

Impact

Exploitation of this vulnerability could lead to unauthorized modifications in the database configuration table, potentially causing reduced system performance or interruptions.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. Security fixes for SAP NetWeaver based products are delivered with support packages. For information on the latest SAP Security Patch Day, refer to the SAP Security Patch Day Bulletin.

Added: Mar 10, 2026, 5:46 PM
Updated: Mar 10, 2026, 5:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
3.8
exploitability
5.2
remediation
0.0
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.