#VU125963 Open redirect in SAP NetWeaver AS ABAP - CVE-2026-34257
Published: April 14, 2026
SAP NetWeaver AS ABAP
SAP
Description
The vulnerability allows a remote attacker to redirect users to an arbitrary site and disclose limited information.
The vulnerability exists due to open redirect in SAP NetWeaver Application Server ABAP when handling requests. A remote attacker can trick the victim into opening a crafted link to redirect users to an arbitrary site and disclose limited information.
User interaction is required.