← back
CVE-2026-44749

Information Disclosure vulnerability in SAP Gateway

CVSS 4.3 MEDIUMEPSS 0.3%CWE-497
The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
SAP_SE · SAP Gateway

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →