vulnti.work

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with …

Medium CVSS 4.3
CVECVE-2026-58246
First seen2026-07-28 11:15 UTC
Disclosed2026-07-28 10:16 UTC
Last updated2026-07-28 20:31 UTC
Channel statusauto

Summary

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Lint boundary warnings (1)

The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).

  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://url.sap/sapsecuritypatchday

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD