CVE 9 CRITICAL

Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)_CVE-2026-40128

9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.

AI Analysis

Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) allowing unauthenticated attackers to manipulate file inclusion parameters and view or modify sensitive information.

Basic Information

ID CVE-2026-40128
Source sap
Published Jun 9, 2026 at 00:20

Affected Product

Vendor SAP_SE
Product SAP NetWeaver Application Server Java (Web Container)
Version ENGINEAPI 7.50
Affected Versions SAP_SE SAP NetWeaver Application Server Java (Web Container) ENGINEAPI 7.50

CWE Classification

AI Assessment

AI Score 9 / 10
AI Severity Critical
Vendor SAP
Product SAP NetWeaver Application Server Java (Web Container)
Version ENGINEAPI 7.50

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.