Home

Description

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or availability.

PUBLISHED Reserved 2026-01-21 | Published 2026-02-10 | Updated 2026-02-10 | Assigner sap




LOW: 3.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers

Product status

Default status
unaffected

KRNL64NUC 7.22
affected

7.22EXT
affected

KRNL64UC 7.22
affected

7.53
affected

8.04
affected

KERNEL 7.22
affected

7.54
affected

7.77
affected

7.89
affected

7.93
affected

9.16
affected

9.17
affected

9.18
affected

References

me.sap.com/notes/3678313

url.sap/sapsecuritypatchday

cve.org (CVE-2026-24320)

nvd.nist.gov (CVE-2026-24320)

Download JSON