HomeRisk ManagementsSAP Patches Maximum Severity Overpass Flaw

SAP Patches Maximum Severity Overpass Flaw

Published on

spot_img

Critical Vulnerability Threatens Over 10,000 SAP Systems

A significant security alert has been raised by Onapsis, a reputable security vendor, indicating that over 10,000 internet-exposed SAP systems may be vulnerable to a highly critical flaw in the SAP kernel. This vulnerability, identified as a Memory Corruption issue relating to SAP Extended Passport (EPP) Processing, has been cataloged under the identifier CVE-2026-44756.

Onapsis Research Labs (ORL) took the initiative to discover and responsibly disclose this vulnerability to SAP, providing crucial insights into the potential risks involved. According to their findings, the researchers revealed that there is a lack of boundary validation during the process of deserializing EPP data. This oversight leads to a memory safety violation when processing length fields supplied externally. In a blog post published on September 8, the team explained, “This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination.”

The implications of such a flaw are staggering. Onapsis highlighted that the vulnerability exists in shared kernel code for EPP processing, which is accessible from both the SAP Graphical User Interface (GUI) and the remote function call (RFC) layer linking various SAP systems. The firm has cautioned that this particular vulnerability is remotely exploitable without requiring any form of authentication, and it is present by default across a variety of SAP components.

If successfully exploited, the vulnerability could empower remote attackers to execute arbitrary OS commands on the host SAP system with administrative privileges. Such actions would facilitate a complete compromise of SAP business data and processes, raising substantial concerns for organizations relying on SAP systems for their operations.

Despite the gravity of the situation, Onapsis noted that, at the time of their reporting, there was no active exploitation observed. However, the firm expressed concern that this status could change rapidly, potentially exposing a vast number of systems to malicious attacks.

In addition to the aforementioned vulnerability, Onapsis advised SAP customers to address other critical vulnerabilities as well. One such flaw is identified as CVE-2026-58240, which bears a CVSS score of 9.8. Dubbed "S4GET," this vulnerability affects the Message Server in specific versions of SAP S/4HANA. The potential consequences of this flaw are alarming, as it may allow unauthorized users to gain access to the entire SAP system cluster, thereby enabling the execution of malicious payloads and arbitrary commands from a remote location.

Two other notable vulnerabilities warranting attention include:

  1. CVE-2026-76969: This flaw pertains to credential disclosure in multitenant applications utilizing the SAP Cloud Application Programming Model (CAP). With a CVSS score of 9.4, it poses a serious risk, but this vulnerability is reportedly addressed through SAP Security Note #3798315.

  2. CVE-2026-66768: This vulnerability relates to improper access control within SAP NetWeaver and has a CVSS score of 9.0. The implications of this flaw could lead to arbitrary command execution on a victim’s machine, which is another pressing security concern. This issue can be mitigated using SAP Security Note #3781729.

Onapsis has made a strong appeal for immediate action, particularly emphasizing the need for SAP customers to prioritize the patching of CVE-2026-44756. The growing list of vulnerabilities underlines the critical importance for organizations using SAP systems to stay vigilant and proactive regarding their cybersecurity measures.

As the landscape of cybersecurity continues to evolve, the responsibility falls on SAP users to ensure that their systems are equipped with the latest patches and updates, thereby safeguarding against potential threats that could compromise not only the integrity of their SAP environments but also the sensitive data they contain. Companies are urged to adopt rigorous security practices to mitigate risks and ensure the continued operational health of their SAP systems in an increasingly perilous digital world.

Source link

Latest articles

Former Currys CIO Andy Gamble Appointed Chair of Advisory Board at Core to Cloud

UK cybersecurity specialist Core to Cloud has recently made a significant move in its...

TRM Labs Achieves $2B Valuation Amid AI-Driven Investigations

TRM Platform Leverages AI to Enhance Blockchain Data Analysis Amidst Rising Cyber Threats In a...

FBI Releases Initial Cyber Strategy

On September 9, the FBI made a notable advancement in its approach to combating...

More like this

Former Currys CIO Andy Gamble Appointed Chair of Advisory Board at Core to Cloud

UK cybersecurity specialist Core to Cloud has recently made a significant move in its...

TRM Labs Achieves $2B Valuation Amid AI-Driven Investigations

TRM Platform Leverages AI to Enhance Blockchain Data Analysis Amidst Rising Cyber Threats In a...

FBI Releases Initial Cyber Strategy

On September 9, the FBI made a notable advancement in its approach to combating...