CVE-2026-34257

MEDIUM WAF: Medium
CVSS 6.1 Published: 2026-04-14
CWE-601

Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.

WAF Coverage Analysis

Open Redirect Medium WAF Coverage

OWASP: A01:2021 Broken Access Control

941xxx - XSS / XXE

Affected Software

VendorProductVersion
sapnetweaver_application_server_abap700
sapnetweaver_application_server_abap701
sapnetweaver_application_server_abap702
sapnetweaver_application_server_abap731
sapnetweaver_application_server_abap740
sapnetweaver_application_server_abap750
sapnetweaver_application_server_abap752
sapnetweaver_application_server_abap753
sapnetweaver_application_server_abap754
sapnetweaver_application_server_abap755

References

Back to CVE Database