Information Disclosure vulnerability in SAP Gateway
Summary
| CVE | CVE-2026-44749 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-26 18:16:51 UTC |
| Updated | 2026-05-26 19:08:15 UTC |
| Description | The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.000090000 probability, percentile 0.010090000 (date 2026-05-31)
Problem Types: CWE-497 | CWE-497 CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | CVSS | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP SE | SAP Gateway | affected SAP_GWFND 750 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 751 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 752 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 753 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 754 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 755 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 756 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 757 | Not specified |
| CNA | SAP SE | SAP Gateway | affected 758 | Not specified |
| CNA | SAP SE | SAP Gateway | affected SAP_BASIS 795 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| me.sap.com/notes/3433366 | [email protected] | me.sap.com | |
| url.sap/sapsecuritypatchday | [email protected] | url.sap | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.