CVE-2026-34257
published 2026-04-14CVE-2026-34257: Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a…
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.15%
5.0th percentile
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP NetWeaver Application Server ABAP up to 816 redirect (Nessus ID 306732)
vuldb·2026-04-17·CVSS 6.1
CVE-2026-34257 [MEDIUM] SAP NetWeaver Application Server ABAP up to 816 redirect (Nessus ID 306732)
A vulnerability, which was classified as problematic, was found in SAP NetWeaver Application Server ABAP up to 816. Affected by this issue is some unknown functionality. Executing a manipulation can lead to open redirect.
This vulnerability is handled as CVE-2026-34257. The attack can be executed remotely. There is not any exploit available.
A patch should be applied to remediate this issue.
GHSA
GHSA-fwjv-3fw4-7x83: Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accesse
ghsa_unreviewed·2026-04-14
CVE-2026-34257 [MEDIUM] CWE-601 GHSA-fwjv-3fw4-7x83: Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accesse
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published