[Security Vulnerability Alert] SAP Issues Major Cybersecurity Announcement for Multiple Products

 
2026/8/18 ~ 2027/2/18
View Count:27

Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202608-00000010

[Content Description]
【CVE-2026-58231, CVSS: 10.0】 This vulnerability in SAP Commerce Cloud allows unauthenticated attackers to abuse the default authentication client and submit carefully crafted input to functions lacking complete authentication. Successful exploitation could lead to arbitrary code execution and damage to internal components.

【CVE-2026-34265, CVSS: 9.8】 This vulnerability in SAP NetWeaver and ABAP Platform allows unauthenticated attackers to exploit a logical error in the DIAG protocol parsing, potentially leading to memory corruption, leakage of sensitive system information, or system crashes.

【CVE-2026-44758, CVSS: 9.1】 This vulnerability in SAP Manufacturing Integration and Intelligence allows a high-privilege attacker to submit carefully crafted input to certain affected functions. If this input is not adequately validated, an attacker could exploit this vulnerability to execute arbitrary commands on the underlying operating system.

【CVE-2026-58243, CVSS: 8.8】 Certain functions in SAP ABAP Developer Tools do not perform necessary authorization checks, allowing a low-privilege attacker to perform unauthorized database operations on SAP NetWeaver AS ABAP. Successful exploitation of this vulnerability could lead to an attacker reading sensitive data, modifying application data, and disrupting legitimate user access.

[Influence Platform]
【CVE-2026-58231】 SAP Commerce Cloud (Data Hub Adapter) Version(s) - COM_CLOUD 2211, 2211-JDK21

【CVE-2026-34265】 SAP NetWeaver and ABAP Platform Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19

【CVE-2026-44758】 SAP Manufacturing Integration and Intelligence Version(s) - XMII 15.4, 15.5

【CVE-2026-58243】 SAP ABAP Developer Tools Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920

[Recommended Action]
Patch the issue according to the solution released on the official website: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html?isu_page=1

[References]
1. https://www.twcert.org.tw/tw/cp-169-11102-6a741-1.html

Files
system_update_alt官方網站
system_update_alt參考資料
Top↑