Open Redirect Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2026-34257

6.1MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
14 April 2026

What is CVE-2026-34257?

An Open Redirect vulnerability in SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a malicious URL that can redirect users to a location controlled by the attacker. This threat can undermine the confidentiality and integrity of the application by misleading users into visiting harmful sites, thereby exposing them to potential phishing attacks and data theft.

Affected Version(s)

SAP NetWeaver Application Server ABAP SAP_BASIS 700

SAP NetWeaver Application Server ABAP SAP_BASIS 701

SAP NetWeaver Application Server ABAP SAP_BASIS 702

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.