[Security Vulnerability Alert] SAP Issues Major Cybersecurity Announcement for Multiple Products

 
2026/1/16 ~ 2026/7/16
View Count:27

Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202601-00000012

[Content Description]
【CVE-2026-0501, CVSS: 9.9】 This vulnerability exists in SAP S/4HANA private cloud and on-premises deployments (Financials – General Ledger). Due to insufficient input validation, it allows authenticated attackers to use specially crafted SQL commands to read, modify, and delete backend database data.

【CVE-2026-0500, CVSS: 9.6】 Because SAP Wily Introscope Enterprise Manager (WorkStation) uses vulnerable third-party components, unauthenticated attackers can create malicious JNLP files with publicly accessible URLs. When a victim clicks the URL, the Wily Introscope server can execute operating system commands on the victim's computer.

【CVE-2026-0498, CVSS: 9.1】This vulnerability exists in SAP S/4HANA's private cloud and on-premises deployments. It allows an attacker with administrator privileges to inject arbitrary ABAP code/operating system commands into the system by exploiting a vulnerability in a function module exposed in an RFC, thereby bypassing necessary authorization checks.

【CVE-2026-0491, CVSS: 9.1】This vulnerability in SAP Landscape Transformation allows an attacker with administrator privileges to exploit a vulnerability in a function module exposed in an RFC, thereby injecting arbitrary ABAP code/operating system commands into the system, thereby bypassing necessary authorization checks.

【CVE-2026-0492, CVSS: 8.8】This vulnerability in SAP HANA databases allows an attacker with valid user credentials to switch users and gain administrator privileges.

[Affected Platforms]
SAP S/4HANA Private Cloud and On-Premise (Financials – General Ledger) S4CORE versions 102, 103, 104, 105, 106, 107, 108, 109

SAP Wily Introscope Enterprise Manager (WorkStation) WILY_INTRO_ENTERPRISE version 10.8

SAP S/4HANA (Private Cloud and On-Premise) S4CORE versions 102, 103, 104, 105, 106, 107, 108, 109

SAP Landscape Transformation DMIS versions 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731 Version 2018_1_752, 2020

SAP HANA database HDB version 2.00

[Recommended Action]
Patch according to the solution released on the official website: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html

[References]
1. https://www.twcert.org.tw/tw/cp-169-10634-69895-1.html

Files
None
Top↑