Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap abap Platform Sap application Server Sap netweaver Sap netweaver Abap Sap netweaver Abap Application Server |
|
| Vendors & Products |
Sap
Sap abap Platform Sap application Server Sap netweaver Sap netweaver Abap Sap netweaver Abap Application Server |
Tue, 13 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected. | |
| Title | Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-01-13T18:58:20.906Z
Reserved: 2025-12-09T22:06:46.070Z
Link: CVE-2026-0506
Updated: 2026-01-13T18:57:59.487Z
Status : Awaiting Analysis
Published: 2026-01-13T02:15:53.277
Modified: 2026-01-13T14:03:18.990
Link: CVE-2026-0506
No data.
OpenCVE Enrichment
Updated: 2026-01-13T09:26:57Z