Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44748

Опубликовано: 09 июн. 2026
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application.

EPSS

Процентиль: 14%
0.00231
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.9
github
около 2 месяцев назад

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application.

CVSS3: 9.9
fstec
около 2 месяцев назад

Уязвимость SAML-аутентификации программных интеграционных платформ SAP NetWeaver AS ABAP и SAP NetWeaver ABAP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.00231
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-347