HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-23689

CVSS 7.7v3.1pub. 2026-02-10upd. 2026-02-17

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
  • Sap Advanced Planning And Optimization

    APP
    Sap
    713714
  • Sap Supply Chain Management

    APP
    Sap
    700701702712
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2025-42999CRITICAL9.1⚠ KEVPL ✓same vendor

SAP NetWeaver Visual Composer — niebezpieczna deserializacja treści

CVE-2025-31324CRITICAL10.0⚠ KEVPL ✓same vendor

SAP NetWeaver: nieautoryzowany upload plików wykonywalnych w Visual Composer

CVE-2022-22536CRITICAL10.0⚠ KEVPL ✓same vendor

Request Smuggling w SAP NetWeaver i SAP Web Dispatcher — CVSS 10.0

CVE-2021-38163CRITICAL9.9⚠ KEVPL ✓same vendor

SAP NetWeaver Visual Composer — RCE przez path traversal przy uploadzie pliku

CVE-2020-6287CRITICAL10.0⚠ KEVPL ✓same vendor

SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard