CVE-2026-27671
Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.8EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
09 jun 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
SAP_SE · SAP NetWeaver AS ABAP and ABAP PlatformQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →