CVE-2026-34265

9.8

SAP_SE · SAP NetWeaver and ABAP Platform

SAP NetWeaver and ABAP Platform contain an out-of-bounds write vulnerability in the DIAG protocol parsing logic, enabling unauthenticated remote attackers to trigger memory corruption.

Executive summary

A critical memory corruption vulnerability in SAP NetWeaver and ABAP Platform allows unauthenticated attackers to execute arbitrary code or crash the system via malformed DIAG protocol packets.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) occurring during the parsing of the DIAG protocol. An unauthenticated attacker can send specially crafted packets to the server, leading to memory corruption, information disclosure, or potential system instability.

Business impact

The vulnerability affects the core communication protocol of SAP systems, making it a high-value target. Successful exploitation can lead to a complete denial of service or the exposure of sensitive business intelligence, significantly impacting the availability and confidentiality of the entire SAP infrastructure.

Remediation

Immediate Action: Apply the relevant security patches provided by SAP via the SAP Support Portal, specifically referencing note 3714806.

Proactive Monitoring: Monitor network traffic for malformed or suspicious DIAG protocol requests targeting SAP application servers.

Compensating Controls: Use network segmentation and firewalls to restrict access to SAP application ports to trusted IP ranges only, reducing the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of SAP environments, organizations must prioritize the application of the vendor-provided patches. Evaluate the exposure of your SAP NetWeaver instances and ensure that all necessary security notes are implemented as part of standard maintenance cycles.

More SAP_SE CVEs