CVE-2026-34257: Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34257?
CVE-2026-34257 is classified as a high severity vulnerability due to its potential for exploitation through crafted URLs.
How do I fix CVE-2026-34257?
To fix CVE-2026-34257, appropriate patches or updates for SAP NetWeaver Application Server ABAP should be applied as recommended by SAP.
Who is affected by CVE-2026-34257?
CVE-2026-34257 affects users of the SAP NetWeaver Application Server ABAP, specifically those who do not implement proper security measures against open redirect vulnerabilities.
What impacts can CVE-2026-34257 have on an organization?
CVE-2026-34257 can lead to unauthorized access and phishing attacks by redirecting users to malicious sites if exploited.
Is CVE-2026-34257 an authenticated or unauthenticated vulnerability?
CVE-2026-34257 is an unauthenticated vulnerability, meaning that attackers do not need to be logged in to exploit it.