SAP Application Server ABAP Privilege Escalation Vulnerability via Inadequate Authorization Checks

Vulnerability

A vulnerability in the SAP Application Server ABAP has been identified, where the application fails to implement necessary authorization checks for authenticated users. This flaw allows an attacker to execute a report generation command that could overwrite information belonging to another user, leading to unauthorized privilege escalation. The vulnerability has a high impact on data integrity, a low impact on availability, and no impact on confidentiality.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation by allowing an authenticated user to overwrite another user's information, thereby manipulating access rights or roles within the application.

Remediation

Users are advised to consult the SAP Security Notes for guidance on applying necessary patches. SAP Security Notes can be accessed through the SAP for Me platform, specifically on the SAP Security Patch Day.

Added: Jun 9, 2026, 1:22 AM
Updated: Jun 9, 2026, 1:22 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
5.0
exploitability
4.9
remediation
5.6
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.