【資安漏洞預警】SAP針對旗下多款產品發布重大資安公告
【Security Vulnerability Alert】SAP has released critical security advisories for multiple products under its portfolio

發布單位:圖資處數位服務組
日期範圍:2026/7/23 ~ 2027/1/23
 
發布單位:圖資處數位服務組
日期範圍:2026/7/23 ~ 2027/1/23
行政 行政公告
全體

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000008

[內容說明]
【CVE-2026-44747,CVSS:9.9】 SAP NetWeaver Application Server ABAP 允許經過身分驗證的攻擊者利用記憶體管理的邏輯錯誤造成記憶體損壞,導致未經授權的資料存取、修改或系統無法使用。

【CVE-2026-27690,CVSS:9.1】 SAP Approuter 中存在 HTTP 請求走私漏洞(HTTP Request Smuggling vulnerability),未經身分驗證的攻擊者可以發送精心設計的 HTTP 請求,導致請求回應不同步,導致洩漏用戶回應資料,並影響系統無法使用。

【CVE-2026-44761,CVSS:9.1】 SAP Commerce Cloud 可能保留範例 OAuth2 用戶端,其中包含公開記錄的範例憑證,這些憑證源自 SAP 說明入口網站文件中提供的範例設定。未經身份驗證的攻擊者可利用公開憑證來取得有效的token,並呼叫某些 API 讀取和修改資料。

[影響平台]
SAP NetWeaver Application Server ABAP Version(s) - KRNL64NUC 7.22, 722EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53. 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20

SAP Approuter Version(s) - SAP Approuter node.js package < 20.10.0
 
SAP Commerce Cloud Version(s) - HY_COM 2205, COM_CLOUD 2211, 2211-JDK21

[建議措施]
根據官方網站釋出的解決方式進行修補:https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html

Forward Taiwan Computer Emergency Response Team/Coordination Center Cybersecurity Alert TWCERTCC-200-202607-00000008

[Description]
【CVE-2026-44747,CVSS:9.9】 SAP NetWeaver Application Server ABAP allows authenticated attackers to exploit a logic error in memory management to cause memory corruption, leading to unauthorized data access, modification, or system unavailability.

【CVE-2026-27690,CVSS:9.1】 An HTTP Request Smuggling vulnerability exists in SAP Approuter. An unauthenticated attacker can send specially crafted HTTP requests, causing request-response desynchronization, leading to leakage of user response data and affecting system availability.

【CVE-2026-44761,CVSS:9.1】 SAP Commerce Cloud may retain sample OAuth2 clients containing publicly documented example credentials, which originate from sample configurations provided in SAP Help Portal documentation. An unauthenticated attacker can use the public credentials to obtain valid tokens and call certain APIs to read and modify data.

[Affected Platforms]
SAP NetWeaver Application Server ABAP Version(s) - KRNL64NUC 7.22, 722EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53. 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20

SAP Approuter Version(s) - SAP Approuter node.js package < 20.10.0
 
SAP Commerce Cloud Version(s) - HY_COM 2205, COM_CLOUD 2211, 2211-JDK21

[Recommendations]
Apply patches according to the solutions released on the official website: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
system_update_alt官方網站
Top↑