[CIAD-2026-0001] Multiple Vulnerabilities in SAP Products

By Published On: January 14, 2026

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in SAP Products 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: High
Software Affected
SAP S/4HANA Private Cloud and On-Premise (Financials  General Ledger)
SAP Wily Introscope Enterprise Manager (WorkStation)
SAP S/4HANA (Private Cloud and On-Premise)
SAP Landscape Transformation
SAP HANA database
SAP Application Server for ABAP and SAP NetWeaver RFCSDK
SAP Fiori App (Intercompany Balance Reconciliation)
SAP NetWeaver Application Server ABAP and ABAP Platform
SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)
SAP NetWeaver Enterprise Portal
SAP Business Connector
SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
SAP Fiori App (Intercompany Balance Reconciliation)
Business Server Pages Application (Product Designer Web UI)
SAP Identity Management
NW AS Java UME User Mapping
Overview
Multiple vulnerabilities have been reported in SAP products which could allow an attacker to perform Sql injection, cross-site scripting (XSS) attacks, escalate privileges, inject arbitrary code, bypass security restriction, open redirect, disclose sensitive information and perform CSRF (Cross-Site Request Forgery) on the targeted system.
Target Audience:
SAP system administrators, SAP security teams, IT infrastructure teams managing SAP landscape and Application developers using affected SAP.
Risk Assessment:
Privilege escalation, code or command execution, data manipulation or disclosure, authentication bypass, and redirection of users to malicious resources
Impact Assessment:
Execution of arbitrary code or commands, potential for system compromise, Unauthorized access, data exposure, privilege abuse, User redirection facilitating phishing or credential theft, High risk of data breach.
Description
Multiple vulnerabilities have been reported in SAP products.
 
Solution
Apply appropriate fixes as mentioned in SAP Security Advisory:  
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html
Vendor Information
SAP
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html
References
SAP
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html
CVE Name
CVE-2026-0491
CVE-2026-0492
CVE-2026-0493
CVE-2026-0494
CVE-2026-0495
CVE-2026-0496
CVE-2026-0497
CVE-2026-0498
CVE-2026-0499
CVE-2026-0500
CVE-2026-0501
CVE-2026-0503
CVE-2026-0504
CVE-2026-0506
CVE-2026-0507
CVE-2026-0510
CVE-2026-0511
CVE-2026-0513
CVE-2026-0514
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmlnq5EACgkQ3jCgcSdc
ys8ZHRAAqJqEvTp5Khi3Mcy/7AcosHtnQ3V6sskanJqnkSqVaqYHHLRtjZ04YwKj
7HjHbLvCQlnVammMAa5lvml1bp0SQBxL6OccHZJacwiP+Tj/+IN4n9awFtw/CGF/
p0qwVigkkWq/J0Yypvny36GhdqVctglmDf3QOQMaAYrWnLpWF5F1/9wmW9jYzrfX
eVefZuEtY5dh1xA/MgngDJcvwLF5n35czb3/qjzclfVG458YW47aKlZOlfbUhwfD
uvwtRb7lVAHdnN7WPdgeGcx0nqxmFDl7JEdTmtJEeMpkRPmj0x9ghe/nlzeCUZpH
BnhygmYhWsceBqV84yj4UEXiWxkRthUekV0XlpICykOedOZ2vGfQ7/ihdCP7ZrlQ
fxfFfk/TOTgt0wPFs+o2YSMbLZ8JuuAmRvQo09KziVHDJc1K5It63ECKzsp8ejk3
zgqG+TW1EzNXztOcoHepVTT/S/oFAZ2OcXhhuM+8IS2ZwvPctuzWLLvlTwfKoL1s
I8f/X5F4vINx1JaHBZeMJnG7b43JJXm+1R/rjixVe2/vzkrPB8boNi94KoDSGDwy
+pHfoVySAMRWk8ylmm9kkAf2myN4o7gBXBfDtL9WLpDt5YDh5oBmOwIJt8fNliln
n3jNIbkBMHf9WL26VyQ4GyEcZbZuNw10NytC+FiNVuOxtwV4JA4=
=FTDI
—–END PGP SIGNATURE—–

Share this article