VDB

GCVE-110-NCSC-2026-230

GCVE-110-NCSC-2026-230
Advisory PublishedCVSS 9.9/10
Vulnetix · Advisory published July 14, 2026
SAP NetWeaver Application Server ABAP contains a memory management logical error that can be exploited by an authenticated attacker to cause memory corruption, potentially compromising data confidentiality, integrity, and system availability.

Weaknesses (CWE)

CWE-787Out-of-bounds WriteCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-1392Use of Default CredentialsCWE-35Path Traversal: '.../...//'CWE-502Deserialization of Untrusted DataCWE-427Uncontrolled Search Path ElementCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-303Incorrect Implementation of Authentication AlgorithmCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-862Missing AuthorizationCWE-15External Control of System or Configuration SettingCWE-204Observable Response DiscrepancyCWE-297Improper Validation of Certificate with Host MismatchCWE-178Improper Handling of Case Sensitivity

Risk Scores

CVSS 3.1
9.9/10
Critical · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
SAPvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

75,875 records in the GCVE database · Updated August 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›