Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
History

Tue, 09 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Netweaver And Abap Platform
Vendors & Products Sap Se
Sap Se sap Netweaver And Abap Platform

Tue, 09 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Description Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
Title Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-06-09T00:20:04.299Z

Reserved: 2026-02-23T17:50:10.512Z

Link: CVE-2026-27671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T01:16:45.903

Modified: 2026-06-09T02:08:28.150

Link: CVE-2026-27671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T02:30:26Z