← Back
Enterprise SaaS
CVE-2026-76967 high CVSS 7.8

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could r...

Summary

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted...

AI summary openai / gpt-4o

SAP NetWeaver Business Clientは、アプリケーション起動時に特定のローカルデータを処理する際の検証が不十分です。これにより、低権限の攻撃者が特別に細工したデータでこれを置き換えることができ、ユーザーのコンテキスト内で任意のコードを実行される可能性があります。
❓ What is the problem
SAP NetWeaver Business Clientにおける不十分なデータ検証の脆弱性。
📍 Affected scope
SAP NetWeaver Business Client アプリケーションの起動時。
🔥 Severity
低権限の攻撃者が任意のコードを実行する可能性があり、機密性、完全性、可用性に高い影響を与える。
🔧 How to fix
SAP提供の最新パッチを適用してください。
🛡️ Workaround
情報なし
🔍 Detection
システムのローカルデータの改ざんがないか確認してください。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →