SAP Releases Security Updates For Critical Commerce Cloud And NetWeaver Vulnerabilities

Published:

SAP has released a new set of security updates to address several critical vulnerabilities affecting its enterprise software portfolio, including a maximum severity flaw in SAP Commerce Cloud that could allow unauthenticated attackers to execute arbitrary code. The most serious issue, tracked as CVE 2026 58231, carries a CVSS score of 10.0 and affects the Commerce Cloud Data Hub Adapter. According to SAP, the vulnerability results from insufficient authorization checks and inadequate input validation, allowing attackers to exploit a default authentication client by submitting specially crafted requests. Successful exploitation could enable arbitrary code execution and compromise internal application components, potentially affecting the confidentiality, integrity, and availability of enterprise environments running the vulnerable software.

The company explained that the vulnerability allows an unauthenticated attacker to target specific functions that lack sufficient input validation, making it possible to execute malicious code without prior authentication. SAP security specialist Onapsis has urged customers to apply the latest Commerce Cloud updates and redeploy the patched software as soon as possible. For organizations that cannot immediately install the updates, Onapsis recommended implementing an IP Filter Set to restrict access to the vulnerable endpoint as a temporary mitigation measure until patching can be completed. The advisory emphasizes that prompt remediation is essential because vulnerabilities with a CVSS score of 10.0 represent the highest level of risk under the Common Vulnerability Scoring System and can expose enterprise systems to severe security impacts if left unpatched.

Alongside the Commerce Cloud vulnerability, SAP also addressed three additional critical security flaws as part of its August 2026 Security Patch Day. These include CVE 2026 44772, a code injection vulnerability with a CVSS score of 9.9 affecting Manufacturing Integration and Intelligence, and CVE 2026 34265, a vulnerability rated 9.8 impacting Application Server ABAP for SAP NetWeaver and ABAP Platform. According to SAP, the NetWeaver flaw is an out of bounds write vulnerability that enables unauthenticated attackers to exploit logical errors in DIAG protocol parsing, potentially leading to memory corruption, disclosure of sensitive information, or denial of service through system crashes. SAP also resolved CVE 2026 44758, a code injection vulnerability with a CVSS score of 9.1 in Manufacturing Integration and Intelligence that could allow a highly privileged attacker to execute arbitrary operating system commands.

Onapsis provided additional technical details regarding the Manufacturing Integration and Intelligence vulnerabilities, explaining that CVE 2026 44758 involves a servlet component vulnerable to server side template injection and server side request forgery, which could ultimately enable command execution. SAP’s update removes the affected servlet component to eliminate the security risk. The second Manufacturing Integration and Intelligence vulnerability, CVE 2026 44772, allows a low privileged attacker to submit specially crafted input that causes the application to retrieve and process attacker controlled content from external sources, potentially resulting in arbitrary command execution on the underlying host. Following installation of the security update, SAP requires customers to configure a new Secure Transformer system property specifying approved hosts for XSL files, ensuring that only trusted sources can be processed by the application. The latest security updates reinforce the importance of timely patch management for organizations operating SAP enterprise platforms to reduce exposure to critical vulnerabilities and protect business critical systems from potential compromise.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img