CVE Explorer
CVE-2026-44747
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SAP NetWeaver Application Server ABAP","vendor":"SAP_SE","versions":[{"status":"affected","version":"KRNL64NUC 7.22"},{"status":"affected","version":"7.22EXT"},{"status":"affected","version":"KRNL64UC 7.22"},{"status":"affected","version":"7.53"},{"status":"affected","version":"KERNEL 7.22"},{"status":"affected","version":"7.53. 7.54"},{"status":"affected","version":"7.77"},{"status":"affected","version":"7.93"},{"status":"affected","version":"9.16"},{"status":"affected","version":"9.18"},{"status":"affected","version":"9.19"},{"status":"affected","vers…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:45d1013f53eb1c71e9b359251347e82743ed903aceee0eceab2d5841469797e8 · sha256:51498d58a09b07e7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:45d1013f53eb1c71e9b359251347e82743ed903aceee0eceab2d5841469797e8 · sha256:51498d58a09b07e7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-787","description":"CWE-787: Out-of-bounds Write","lang":"eng","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:45d1013f53eb1c71e9b359251347e82743ed903aceee0eceab2d5841469797e8 · sha256:51498d58a09b07e7… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://me.sap.com/notes/3747367"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:45d1013f53eb1c71e9b359251347e82743ed903aceee0eceab2d5841469797e8 · sha256:51498d58a09b07e7… · /containers/cna/references/0
{"url":"https://url.sap/sapsecuritypatchday"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:45d1013f53eb1c71e9b359251347e82743ed903aceee0eceab2d5841469797e8 · sha256:51498d58a09b07e7… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.