CVE-2026-44749
Description
The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SAP Gateway error message content injection allows attackers to leak request artifacts such as regex patterns, revealing URI parsing logic with low confidentiality impact.
Vulnerability
The SAP Gateway contains a content injection vulnerability in error message handling. An attacker can inject content into error responses, causing the disclosure of request artifacts such as regex patterns and revealing underlying URI parsing logic. This issue affects SAP Gateway systems as described in SAP Security Notes published on Patch Day [1]. No specific version numbers are provided in the available references.
Exploitation
An attacker requires network access to the SAP Gateway service. No authentication is required. By crafting a request with specially chosen values that trigger error responses, the attacker can inject content that is reflected back in the error message, thereby revealing internal processing details such as regex patterns and URI parsing logic.
Impact
Successful exploitation leads to low impact on confidentiality as defined by the CVSS v3 score of 4.3 (Medium). The attacker gains insight into the Gateway's URI parsing logic and related request artifacts, which could aid in further attacks. Integrity and availability are not affected.
Mitigation
SAP has released security notes addressing this vulnerability as part of its regular SAP Security Patch Day [1]. Customers should apply the relevant SAP Security Notes for their Gateway installations. Affected systems should be updated to the latest support packages that include the fix as per SAP's maintenance strategy for low and medium severity notes [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.