SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 09 Jun 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable. | |
| Title | Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-06-09T00:20:14.581Z
Reserved: 2026-04-09T17:29:44.662Z
Link: CVE-2026-40128
No data.
Status : Awaiting Analysis
Published: 2026-06-09T01:16:46.050
Modified: 2026-06-09T02:08:28.150
Link: CVE-2026-40128
No data.
OpenCVE Enrichment
Updated: 2026-06-09T03:00:14Z
Weaknesses