CVE-2026-24320 Details
Description
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or availability.
A vulnerability exists in SAP NetWeaver and ABAP Platform (Application Server ABAP) due to improper memory management. An authenticated attacker could exploit logical errors by sending specially crafted input with unique characters that are incorrectly processed. This exploitation may lead to memory corruption and the unintentional leakage of memory contents. While the vulnerability could allow for some confidentiality loss, it does not impact the application's integrity or availability.
Security fixes for this vulnerability will be included in the SAP Security Patch Day updates. The next scheduled SAP Security Patch Day is on March 10, 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3678313 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-113 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap netweaver as abap kernel | 7.22 7.54 7.77 7.89 7.93 9.16 9.17 9.18 |
CPE
Remediation
| |
| sap netweaver as abap krnl64nuc | 7.22 7.22ext |
CPE
Remediation
| |
| sap netweaver as abap krnl64uc | 7.22 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | Initial Analysis | [email protected] |
| Feb 10, 2026 | New CVE Received | [email protected] |