SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.
Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Problem type
Affected products
SAP_SE
SAP_BASIS 740 - AFFECTED
SAP_BASIS 750 - AFFECTED
SAP_BASIS 751 - AFFECTED
SAP_BASIS 752 - AFFECTED
SAP_BASIS 753 - AFFECTED
SAP_BASIS 754 - AFFECTED
SAP_BASIS 755 - AFFECTED
SAP_BASIS 756 - AFFECTED
SAP_BASIS 757 - AFFECTED
SAP_BASIS 758 - AFFECTED
SAP_BASIS 795 - AFFECTED
References
GitHub Security Advisories
GHSA-h2jw-cxmg-w6mx
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier...
https://github.com/advisories/GHSA-h2jw-cxmg-w6mxSAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-58246Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-58246",
"assignerOrgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
"assignerShortName": "sap",
"dateUpdated": "2026-07-28T09:51:55.180Z",
"dateReserved": "2026-06-29T19:35:04.186Z",
"datePublished": "2026-07-28T09:51:55.180Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
"shortName": "sap",
"dateUpdated": "2026-07-28T09:51:55.180Z"
},
"title": "Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform",
"descriptions": [
{
"lang": "en",
"value": "SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<div><p>SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.</p></div><br>"
}
]
}
],
"affected": [
{
"vendor": "SAP_SE",
"product": "SAP NetWeaver Application Server for ABAP",
"platforms": [
"ABAP"
],
"defaultStatus": "unaffected",
"versions": [
{
"version": "SAP_BASIS 740",
"status": "affected"
},
{
"version": "SAP_BASIS 750",
"status": "affected"
},
{
"version": "SAP_BASIS 751",
"status": "affected"
},
{
"version": "SAP_BASIS 752",
"status": "affected"
},
{
"version": "SAP_BASIS 753",
"status": "affected"
},
{
"version": "SAP_BASIS 754",
"status": "affected"
},
{
"version": "SAP_BASIS 755",
"status": "affected"
},
{
"version": "SAP_BASIS 756",
"status": "affected"
},
{
"version": "SAP_BASIS 757",
"status": "affected"
},
{
"version": "SAP_BASIS 758",
"status": "affected"
},
{
"version": "SAP_BASIS 795",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-497 Exposure of sensitive system information to an unauthorized control sphere",
"cweId": "CWE-497",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/3413033"
},
{
"url": "https://url.sap/sapsecuritypatchday"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
}
}
]
}
}
}