SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable. | |
| Title | Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-06-09T00:20:14.581Z
Reserved: 2026-04-09T17:29:44.662Z
Link: CVE-2026-40128
No data.
Status : Awaiting Analysis
Published: 2026-06-09T01:16:46.050
Modified: 2026-06-09T02:08:28.150
Link: CVE-2026-40128
No data.
OpenCVE Enrichment
Updated: 2026-06-09T03:00:14Z