PatchSiren

SAP_SE CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM SAP_SE CVE published 2026-06-09

CVE-2026-24315

CVE-2026-24315 is a vulnerability in SAP Fiori Launchpad that allows attackers to craft malicious URLs, potentially leading to account compromise by stealing user credentials. The vulnerability has a CVSS score of 4.2 and is classified as MEDIUM severity. Successful exploitation requires advanced knowledge of the system and has a low impact on Confidentiality and Integrity, with no impact on Availability.

MEDIUM SAP_SE CVE published 2026-05-26

CVE-2026-44749

A content injection vulnerability in SAP Gateway allows authenticated attackers to manipulate error messages, potentially exposing request artifacts such as regex patterns and URI parsing logic. The vulnerability has a CVSS 3.1 score of 4.3 (Medium severity) with low impact on confidentiality; integrity and availability are unaffected. The issue was published by NVD on 2026-05-26 and classified under CWE- [truncated]

HIGH SAP_SE CVE published 2026-02-10

CVE-2026-23687

CVE-2026-23687 is a HIGH severity vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform. An authenticated attacker with normal privileges can exploit this vulnerability to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data, and potential disruptio [truncated]