Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3692004
was released on
14.04.2026 and deals with
"3692004 - [CVE-2026-34257] Open Redirect vulnerability in SAP NetWeaver Application Server ABAP" within SAP NetWeaver Application Server ABAP.
We advice you to follow the instructions, to resolve
open redirect
with a
medium potential for exploitation
in component BC-FES-ITS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
This note has been re-released with 'Correction Instruction' information. SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft malicious URLs that redirect users to attacker-controlled websites, resulting in unauthorized redirection.
Solution
An appropriate URL validation check is now implemented.
The advisory is valid for
- SAP_BASIS 700-702 96
- SAP_BASIS 731 111
- SAP_BASIS 740 120
- SAP_BASIS 750 118
- SAP_BASIS 752-816 3
