- Description
- SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.
- Source
- cna@sap.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Primary
- Base score
- 9
- Impact score
- 6
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- cna@sap.com
- CWE-35
- Hype score
- Not currently trending
Warning: #SAP has released security updates for 15 vulnerabilities in several of their products, including 4 critical vulnerabilities: #CVE-2026-44748; #CVE-2026-27671; #CVE-2026-40128 and #CVE-2026-22732. Read our advisory here: https://t.co/cVlLvwsEYZ #Patch #Patch #Patch
@CCBalert
9 Jun 2026
107 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Critical - Two SAP NetWeaver Flaws Patched in June 2026 (CVE-2026-44748, CVE-2026-40128) SAP's June 2026 Security Patch Day fixes two critical SAP NetWeaver vulnerabilities, both with a scope change and full C/I/A impact. CVE-2026-44748 (9.9) - AS ABAP and ABAP Platform: an
@UpwindMDR
9 Jun 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-40128 — CVSS 9/10 █████████░ SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/UuRC9R35Aj
@OrizonCyber
9 Jun 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes