← 戻る
Webアプリケーション
CVE-2026-66767 high CVSS 7.7

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentia...

概要

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could r...

AI要約 openai / gpt-4o

SAP NetWeaver Application Serverの脆弱性により、認証されていないユーザーが特別に細工されたデータパケットを送信し、以前にバッファされたユーザー要求を再処理させることができます。これにより、他のユーザーのセッションが乗っ取られる可能性があります。この攻撃は機密性と完全性に高い影響を与える可能性があります。
❓ 何が問題か
SAP NetWeaver Application Serverの脆弱性により、細工されたパケットでユーザー要求の再処理が可能。
📍 影響範囲
SAP NetWeaver Application Server for ABAP and ABAP Platform
🔥 重要度
機密性と完全性に高い影響を及ぼす可能性。低い影響の可用性。
🔧 修正方法
SAPからの公式パッチを適用。
🛡️ 暫定回避
認証プロセスの強化による一時的なリスク軽減策。
🔍 検知方法
ログとネットワークトラフィックを監視し、不審な活動を検出。

参照URL

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →