
[CIAD-2026-0045] Multiple Vulnerabilities in SAP Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in SAP Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: High
Software Affected
SAP Extended Passport (EPP) Processing
SAP NetWeaver (Message Server)
SAP Cloud Application Programming Model (CAP)
SAP NetWeaver (SAP GUI for Java)
SAP ABAP Developer Tools
SAP Integration Suite
SAP NetWeaver Business Client
SAP NetWeaver Application Server for ABAP and ABAP Platform
SAP Commerce Cloud (Search And Navigation)
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
SAP S/4HANA (Intercompany Matching and Reconciliation)
SAP Manufacturing Integration and Intelligence
SAPUI5 (Frame Options Allowlist)
SAP S/4HANA (Finance for Advanced Payment Management)
SAP S/4HANA (Manage Bank Chains app)
SAP NetWeaver and ABAP Platform
SAP Process Integration (SOAP Adapter)
Overview
Multiple vulnerabilities have been reported in various SAP products which could allow a remote attacker to execute arbitrary code, elevate privileges, obtain sensitive information, bypass security restrictions, cause memory corruption, cause denial of service (DoS) conditions, gain unauthorized access, manipulate application data, and perform server-side request forgery (SSRF) on the targeted system.
Target Audience:
Users of SAP products.
Risk Assessment:
High risk of complete system compromise, unauthorized access, and denial of service.
Impact Assessment:
Potential for execute arbitrary code, elevate privileges, disclose sensitive information, and cause denial of service (DoS) conditions.
Description
SAP provides a wide range of enterprise software solutions, including application servers, integration suites, and business process management tools used to manage critical business operations.
These vulnerabilities exist in various SAP products due to memory corruption, missing authentication, credential disclosure, improper access control, XML external entity (XXE) vulnerabilities, insecure deserialization, injection flaws, security misconfigurations, and missing authorization checks. A remote attacker could exploit these vulnerabilities by sending specially crafted requests to the targeted systems.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, elevate privileges, obtain sensitive information, bypass security restrictions, cause memory corruption, cause denial of service (DoS) conditions, gain unauthorized access, manipulate application data, and perform server-side request forgery (SSRF) on the targeted system.
Solution
Apply appropriate fixes as mentioned in SAP Security Advisory:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html
Vendor Information
SAP
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html
References
SAP
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html
CVE Name
CVE-2026-44756
CVE-2026-58240
CVE-2026-76969
CVE-2026-66768
CVE-2026-58243
CVE-2026-76958
CVE-2026-76967
CVE-2026-66767
CVE-2026-2332
CVE-2026-76968
CVE-2026-44766
CVE-2026-76971
CVE-2026-34477
CVE-2026-76977
CVE-2026-76960
CVE-2026-76961
CVE-2026-76959
CVE-2026-76962
CVE-2026-76963
CVE-2026-58234
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqixTwACgkQ3jCgcSdc
ys85hBAAqD+PeK6kgFFJmIzNU+/jn4oFUUu+eFD0Lak/Zm8sLHCsGxcn47n7vSl/
JWRGx+qn5f+xh5rFo7A+lh55ht6e/QfE+XnrmVNKhgV5FawH0sfGdDKC/FEPz2jg
4OEuexFGtp4u6ERLqOERKDVQ09DriS1p6J8NN3fnzqnnoXMaz58gnalmeQphhcXn
mDtO9kQFNFT9jPHG+XSTcKvW9GUD8f4Y+sf/qUiLek7+jTI/HfyBI8XfL0YO9+Cp
hPQqGbkB03G0LL+j+sCqvCoUBp4lcB1TSIugNWGy5+oeWWWlRUuJWqDNu/UJVOwA
ubvOaW7VcE2Ghx17TqPk75Q9/2RwB7UB7mrrJf86UGJIzWtYGXawhqUBteeZ350u
a9IEflHWz9taA/UEtwzFELHDnT069sPoh4p/fTe2tE8LrI0QcayiNlOPR2DhTXFi
4T8TGaJXy/V9ioNv4Enx6tPmjX+JuWnxhN8DJb7Vh8B1VUt5tg6gQQg+/FdGD1O6
ScNKhB6/0BCrVrrETWBH0jARET3KVGVDthDge76syU13MrQUpxagIPrESY+DtgPX
c1JC68hoOBkO7Sx9jol/3VZh4302kJa2cugmNf9gwo60SQdDU/cdfhRLVTMKNBaR
OjCJEyjvOgqfbN8T9H/iwo31/IDTdPcsihzBOuPuPFliJMPZwXc=
=fFpb
—–END PGP SIGNATURE—–


