medium2026-08-11SAP NetWeaverCVE-2026-58246
Information Disclosure in SAP NetWeaver Internet Communication Framework
SAP NetWeaver Internet Communication Framework (ICF)
Our Take
ICF is the HTTP handler underpinning all NetWeaver web services and OData APIs. Information disclosure here can aid reconnaissance. Next planned BASIS window.
Vulnerability Detail
An information disclosure vulnerability in the SAP NetWeaver Internet Communication Framework (ICF) allows an authenticated attacker to access sensitive information beyond their intended permissions via the ICF request/response handling layer.
Patch Action
Apply SAP Note 3413033. Verify affected versions in the official SAP Note.
Patch Info