Sap
5 posts tagged with “Sap”

CVE-2026-58231: Unauthenticated RCE in SAP Commerce Cloud Data Hub Adapter
SAP Commerce Cloud Data Hub Adapter ships with a default authentication client. An unauthenticated attacker can submit crafted input to validation-lacking functions, achieving arbitrary code execution. No fix available yet.

CVE-2026-58243: Privilege Escalation in SAP ABAP Developer Tools
CVE-2026-58243 is a CVSS 8.8 privilege escalation vulnerability in SAP ABAP Developer Tools. A low-privileged user can execute unauthorized database operations against SAP NetWeaver AS ABAP, with high impact on confidentiality, integrity, and availability.

CVE-2026-34265: Unauthenticated Memory Corruption in SAP NetWeaver ABAP DIAG Protocol
CVE-2026-34265 is a CVSS 9.8 unauthenticated memory corruption vulnerability in SAP NetWeaver Application Server ABAP's DIAG protocol parser. Remote attackers can corrupt server memory with no credentials, impacting confidentiality, integrity, and availability.

CVE-2026-44758: Code Injection in SAP Manufacturing Integration and Intelligence
Code injection in SAP MII lets an attacker with high privileges execute arbitrary commands on the OS, with high impact on confidentiality, integrity, and availability at the IT/OT boundary.

CVE-2026-58236: OS Command Injection in SAP NetWeaver Application Server ABAP
OS command injection in SAP NetWeaver Application Server ABAP lets an attacker with high privileges execute OS-level commands on the server, with high availability impact across SAP deployments.