medium2026-07-14SAP NetWeaverCVE-2026-34257

Open Redirect in SAP NetWeaver AS ABAP Internet Transaction Server

SAP NetWeaver AS ABAP (Internet Transaction Server)

Our Take

ITS open redirects are a phishing vector — SAP users clicking an internal-looking link and landing on a credential harvester is a real scenario. Next planned window.

Vulnerability Detail

An open redirect vulnerability in the Internet Transaction Server (ITS) component of SAP NetWeaver AS ABAP allows an unauthenticated attacker to craft a URL that redirects users to an external attacker-controlled domain, enabling phishing attacks targeting SAP users.

Patch Action

Apply SAP Note 3692004. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

6.1

SAP Note

3692004

CVE

CVE-2026-34257

Published

2026-07-14

← All patches