CVE-2026-23686
SAP NetWeaver Application Server Java Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-23686 is a CRLF Injection vulnerability in SAP NetWeaver Application Server Java (version 7.50) that allows an authenticated attacker with administrative access to inject untrusted entries into generated configuration by submitting specially crafted content. Disclosed on February 10, 2026, and patched on SAP Security Patch Day in February 2026, the vulnerability affects only version 7.50 of SAP NetWeaver AS Java. It carries a CVSS v3.1 base score of 3.4 (Medium) (Red Hat CVE, SAP Patch Day).

Detalhes técnicos

The vulnerability is classified under CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers / HTTP Response Splitting) and CWE-436 (Interpretation Conflict). An authenticated administrator can submit specially crafted input containing carriage return and line feed (CRLF) characters, which the application fails to properly neutralize before incorporating the data into generated configuration files or HTTP responses. This allows the attacker to inject arbitrary entries into application-controlled settings, potentially enabling HTTP response splitting or configuration manipulation. Exploitation requires both high privileges (administrative access) and user interaction, significantly limiting the attack surface (Red Hat CVE, SAP Patch Day).

Impacto

Successful exploitation results in a low impact on integrity through manipulation of application-controlled configuration settings; confidentiality and availability are not affected. Because the attacker can inject untrusted entries into generated configuration, there is a risk of altering application behavior or HTTP response headers in ways that could facilitate downstream attacks such as cache poisoning or session fixation against other users. The scope is marked as Changed, indicating that the impact can extend beyond the vulnerable component itself, though the overall severity remains limited given the high privilege requirement (Red Hat CVE).

Mitigação e soluções alternativas

SAP released a patch for this vulnerability as part of SAP Security Patch Day in February 2026; organizations should apply the relevant SAP Security Note available via the SAP Support Portal (SAP Patch Day). As interim measures, restrict administrative access to SAP NetWeaver AS Java to only authorized and trusted personnel, implement input validation and output encoding to neutralize CRLF sequences, and monitor configuration changes for unauthorized modifications. Given the medium severity and high privilege requirement, patching should be prioritized as part of routine SAP maintenance cycles (Red Hat CVE).

Reações da comunidade

The vulnerability was covered as part of broader SAP February 2026 Patch Day roundups by security firms including Onapsis and SecurityBridge, which noted it among several lower-severity issues addressed that month (Onapsis Blog, SecurityBridge Blog). RedRays also published a patch day summary referencing the fix (RedRays Blog). General community sentiment treats this as a routine, low-risk patch given the medium CVSS score and the administrative access prerequisite.

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado SAP NetWeaver Application Server Java Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2025-42944CRITICAL10
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NãoSimSep 09, 2025
CVE-2026-40128CRITICAL9
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NãoSimJun 09, 2026
CVE-2026-27674MEDIUM6.1
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NãoSimApr 14, 2026
CVE-2025-42926MEDIUM5.3
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NãoSimSep 09, 2025
CVE-2026-23686LOW3.4
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NãoSimFeb 10, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adão FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades