CVE-2026-34257

MEDIUM

Open Redirect vulnerability in SAP NetWeaver Application Server ABAP

Title source: cna
STIX 2.1

Description

Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.

Scores

CVSS v3 6.1
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (28)
sap/netweaver_application_server_abap 700
sap/netweaver_application_server_abap 701
sap/netweaver_application_server_abap 702
sap/netweaver_application_server_abap 731
sap/netweaver_application_server_abap 740
sap/netweaver_application_server_abap 750
sap/netweaver_application_server_abap 752
sap/netweaver_application_server_abap 753
sap/netweaver_application_server_abap 754
sap/netweaver_application_server_abap 755
... and 18 more
Published Apr 14, 2026
Tracked Since Apr 14, 2026