Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 10 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap sap Netweaver Application Server Java
Vendors & Products Sap
Sap sap Netweaver Application Server Java

Tue, 10 Feb 2026 03:45:00 +0000

Type Values Removed Values Added
Description Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.
Title CRLF Injection vulnerability in SAP NetWeaver Application Server Java
Weaknesses CWE-113
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-02-10T17:19:05.865Z

Reserved: 2026-01-14T18:26:17.297Z

Link: CVE-2026-23686

cve-icon Vulnrichment

Updated: 2026-02-10T17:19:01.055Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-10T04:16:03.013

Modified: 2026-02-10T15:22:54.740

Link: CVE-2026-23686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-10T15:37:19Z

Weaknesses