Inprosec a través de sus servicios, como el SAP Security Assessment, ayuda a sus clientes a mejorar los niveles de seguridad de sus sistemas SAP.
Notas agosto 2026
Resumen y highlights del Mes
Este mes el número total ha sido de 31 notas (28 nuevas, 1 aviso de seguridad y 2 actualizaciones), 11 más que en julio. Este mes se han publicado 4 Hot News, la misma cantidad que en el periodo anterior. En cuanto a notas de criticidad alta, hay 8, dos más con respecto a julio. Las notas medias y bajas no serán revisadas, por lo que daremos detalle de un total de 12 notas (todas las que tengan un CVSS de 7 o mayor).
Tenemos un total de 31 notas para todo el mes (28 nuevas, 1 aviso de seguridad y 2 actualizaciones de notas de meses anteriores).
Revisaremos en detalle un total de 12 notas, todas de criticidad alta y Hot News:
-
La nota más alta en criticidad del mes (CVSS 10,0) es una Hot News y está relacionada con “Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)”.
-
La segunda nota en criticidad (CVSS 9,9) es otra Hot News y está relacionada con “Code Injection vulnerability in SAP Manufacturing Integration and Intelligence”.
-
La tercera nota en criticidad (CVSS 9,8) es otra Hot News y está relacionada con “Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform”.
-
La cuarta nota en criticidad (CVSS 9,1) es otra Hot News y está relacionada con “Code Injection vulnerability in Manufacturing Integration and Intelligence”.
-
La sexta nota que revisaremos (CVSS 8,8) es de criticidad alta y trata sobre “Privilege Escalation vulnerability in SAP ABAP Developer Tools”.
-
La séptima nota que revisaremos (CVSS 8,1) es de criticidad alta y trata sobre “Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX”.
-
La octava nota que revisaremos (CVSS 7,9) es de criticidad alta y trata sobre “Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)”.
-
La octava nota que revisaremos (CVSS 7,6) es de criticidad alta y trata sobre “Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)”.
-
La novena nota que revisaremos (CVSS 7,6) es de criticidad alta y trata sobre “Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence”.
-
La décima nota que revisaremos (CVSS 7,3) es de criticidad alta y trata sobre “Missing Authorization Check in SAP Manufacturing Integration and Intelligence”.
-
La undécima nota con la misma criticidad (CVSS 7,3) es de criticidad alta y trata sobre “Missing Authorization Check in SAP Manufacturing Integration and Intelligence”.
-
La duodécima y última nota que revisaremos (CVSS 7,0) es de criticidad alta y trata sobre “Multiple vulnerabilities in SAP Business AI Platform (Approuter)”.
Este mes el tipo más predominante ha sido “Missing Authorization Check” (8/31 en el patch day).
En la gráfica podemos ver la clasificación de las notas de agosto, además de la evolución y clasificación de los últimos 5 meses anteriores (solo las notas del Sec. Tuesday / Patch Day – by SAP):
Detalle completo
El detalle completo de las notas más relevantes es el siguiente (en inglés):
-
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) (3771065): SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 10,0/10 [CVE-2026-58231]
-
Code Injection vulnerability in SAP Manufacturing Integration and Intelligence (3765948): SAP Manufacturing Integration and Intelligence allows a low-privileged attacker to submit specially crafted input that causes the application to retrieve and process attacker-controlled content from an external source. Successful exploitation could enable execution of arbitrary commands on the underlying host and impact resources beyond the vulnerable component, resulting in high impact on confidentiality, integrity and availability. CVSS v3 Base Score 9,9/10 [CVE-2026-44772]
-
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform (3714806): SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could disclose confidential system information or crash the system, potentially having a high impact on the confidentiality, integrity, and availability of the application. CVSS v3 Base Score 9,8/10 [CVE-2026-34265]
-
Code Injection vulnerability in Manufacturing Integration and Intelligence (3758900): SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 9,1/10 [CVE-2026-44758]
-
Privilege Escalation vulnerability in SAP ABAP Developer Tools (3772411): SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability. A temporary workaround is available. CVSS v3 Base Score 8,8/10 [CVE-2026-58243]
-
Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX (3773203): An unauthenticated attacker could send specially crafted requests that could trigger memory corruption in an internal process. Exploitation depends on conditions outside the attacker’s control, and on systems where standard memory protections are bypassed. Successful exploitation could lead to arbitrary code execution, resulting in high impact on confidentiality integrity and availability. CVSS v3 Base Score 8,1/10 [CVE-2026-42945]
-
Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) (3756565): SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. CVSS v3 Base Score 7,9/10 [CVE-2026-66763]
-
Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach) (3773304): Enhanced Change and Transport System (CTS+) attach tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application’s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system. CVSS v3 Base Score 7,6/10 [CVE-2026-58233]
-
Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence (3759854): SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker’s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability. A temporary workaround is available. CVSS v3 Base Score 7,6/10 [CVE-2026-44763]
-
Missing Authorization Check in SAP Manufacturing Integration and Intelligence (3758657): Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability. CVSS v3 Base Score 7,3/10 [CVE-2026-44765]
-
Missing Authorization Check in SAP Manufacturing Integration and Intelligence (3758910): Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system. CVSS v3 Base Score 7,3/10 [CVE-2026-44764]
-
Multiple vulnerabilities in SAP Business AI Platform (Approuter) (3786038): This SAP security note addresses several vulnerabilities identified in SAP Approuter. The most critical is an Information Disclosure vulnerability where an unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination, resulting in a high impact on confidentiality and a low impact on integrity and availability. A temporary workaround is available. CVSS v3 Base Score 7,0/10 [CVE-2026-58230]
Enlaces de referencia
Referencias, en inglés de SAP y Onapsis:
Recursos afectados
El listado completo de los sistemas/componentes afectados es el siguiente:
-
SAP Commerce Cloud (and Data Hub Adapter): COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211
-
SAP Manufacturing Integration and Intelligence: XMII 15.4, 15.5, MII_ADMIN 15.4, 15.5
-
SAP NetWeaver and ABAP Platform: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EX2, 7.22EX3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19
-
SAP ABAP Developer Tools: SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920
-
SAP BusinessObjects Business Intelligence Platform (Central Management Server): ENTERPRISE 430, 2025, 2027
-
Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach): CTS_UPLOAD_CLT 1
-
SAP Business AI Platform (Approuter): <23.0.0




