CVE-2026-0484

MEDIUM WAF: Medium
CVSS 6.5 Published: 2026-02-10
CWE-601 CWE-862

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity of the application with no effect on the confidentiality and availability.

WAF Coverage Analysis

Open Redirect Medium WAF Coverage

OWASP: A01:2021 Broken Access Control

941xxx - XSS / XXE
Missing Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
sapsap_basis700
sapsap_basis701
sapsap_basis702
sapsap_basis731
sapsap_basis740
sapsap_basis750
sapsap_basis751
sapsap_basis752
sapsap_basis753
sapsap_basis754

References

Back to CVE Database