The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.
Metrics
Affected Vendors & Products
References
History
Tue, 26 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected. | |
| Title | Information Disclosure vulnerability in SAP Gateway | |
| Weaknesses | CWE-497 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-05-26T18:36:16.647Z
Reserved: 2026-05-07T18:16:34.195Z
Link: CVE-2026-44749
Updated: 2026-05-26T18:36:11.639Z
Status : Awaiting Analysis
Published: 2026-05-26T18:16:51.190
Modified: 2026-05-26T19:08:15.080
Link: CVE-2026-44749
No data.
OpenCVE Enrichment
Updated: 2026-05-26T19:30:13Z