SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 09 Jun 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application. | |
| Title | XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-06-09T03:56:20.892Z
Reserved: 2026-05-07T18:16:34.195Z
Link: CVE-2026-44748
No data.
Status : Awaiting Analysis
Published: 2026-06-09T01:16:46.603
Modified: 2026-06-09T02:08:28.150
Link: CVE-2026-44748
No data.
OpenCVE Enrichment
Updated: 2026-06-09T02:30:26Z
Weaknesses