medium2026-07-14SAP NetWeaverCVE-2026-34257
Open Redirect in SAP NetWeaver AS ABAP Internet Transaction Server
SAP NetWeaver AS ABAP (Internet Transaction Server)
Our Take
ITS open redirects are a phishing vector — SAP users clicking an internal-looking link and landing on a credential harvester is a real scenario. Next planned window.
Vulnerability Detail
An open redirect vulnerability in the Internet Transaction Server (ITS) component of SAP NetWeaver AS ABAP allows an unauthenticated attacker to craft a URL that redirects users to an external attacker-controlled domain, enabling phishing attacks targeting SAP users.
Patch Action
Apply SAP Note 3692004. Verify affected versions in the official SAP Note.
Patch Info