Inprosec a través de sus servicios, como el SAP Security Assessment, ayuda a sus clientes a mejorar los niveles de seguridad de sus sistemas SAP.
Notas julio 2026
Resumen y highlights del Mes
Este mes el número total ha sido de 20 notas (16 nuevas, 1 advisory de seguridad y 3 actualizaciones), 5 más que en junio. Este mes se han publicado 4 Hot News, la misma cantidad que en el periodo anterior. En cuanto a notas de criticidad alta, hay 6, cuatro más con respecto a junio. Las notas medias y bajas no serán revisadas, por lo que daremos detalle de un total de 10 notas (todas las que tengan un CVSS de 7 o mayor).
Tenemos un total de 20 notas para todo el mes (16 nuevas, 1 advisory de seguridad y 3 actualizaciones de notas de meses anteriores).
Revisaremos en detalle un total de 10 notas, todas de criticidad alta y Hot News:
-
La nota más alta en criticidad del mes (CVSS 9,9) es una Hot News y está relacionada con “Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP”.
-
La segunda nota en criticidad (CVSS 9,1) es otra Hot News y está relacionada con “HTTP Request Smuggling in SAP Approuter”.
-
La tercera nota con la misma criticidad (CVSS 9,1) es otra Hot News y está relacionada con “Insecure Sample Credentials in SAP Commerce Cloud”.
-
La cuarta nota en criticidad (CVSS 9,0) es la última Hot News del mes y está relacionada con “Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)”.
-
La quinta nota que revisaremos (CVSS 8,8) es de criticidad alta y trata sobre “Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell)”.
-
La sexta nota que revisaremos (CVSS 8,4) es de criticidad alta y trata sobre “DLL Hijacking vulnerability in SAProuter on Microsoft Windows”.
-
La séptima nota que revisaremos (CVSS 8,2) es de criticidad alta y trata sobre “Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)”.
-
La octava nota que revisaremos (CVSS 8,1) es de criticidad alta y trata sobre “Open Redirect vulnerability in SAP Approuter”.
-
La novena nota con la misma criticidad (CVSS 8,1) es de criticidad alta y trata sobre “Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud”.
-
La décima y última nota que revisaremos (CVSS 7,6) es de criticidad alta y trata sobre “Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)”.
Este mes el tipo más predominante ha sido “Cross-Site Scripting (XSS)” (3/20 en el patch day).
En la gráfica podemos ver la clasificación de las notas de julio, además de la evolución y clasificación de los últimos 5 meses anteriores (solo las notas del Sec. Tuesday / Patch Day – by SAP):
Detalle completo
El detalle completo de las notas más relevantes es el siguiente (en inglés):
-
Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP (3747367): SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 9,9/10 [CVE-2026-44747]
-
HTTP Request Smuggling in SAP Approuter (3720138): Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability. CVSS v3 Base Score 9,1/10 [CVE-2026-27690]
-
Insecure Sample Credentials in SAP Commerce Cloud (3753495): SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability. A temporary workaround is available. CVSS v3 Base Score 9,1/10 [CVE-2026-44761]
-
Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) (3727078): SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable. CVSS v3 Base Score 9,0/10 [CVE-2026-40128]
-
Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell) (3758101): This Security note addresses multiple known vulnerabilities in Apache Camel within SAP Integration Suite. These issues impact message-based header injection and deserialization mechanisms in camel mail and JMS components, allowing attackers to achieve remote code execution and arbitrary file writes on downstream components. It has a high impact on confidentiality, integrity and availability of the application. A temporary workaround is available. CVSS v3 Base Score 8,8/10 [CVE-2026-40860, CVE-2026-40453, CVE-2026-33454]
-
DLL Hijacking vulnerability in SAProuter on Microsoft Windows (3692165): SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system. CVSS v3 Base Score 8,4/10 [CVE-2026-0487]
-
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard) (3748227): SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user’s browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client’s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application. A temporary workaround is available. CVSS v3 Base Score 8,2/10 [CVE-2026-44752]
-
Open Redirect vulnerability in SAP Approuter (3741519): SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application. A temporary workaround is available. CVSS v3 Base Score 8,1/10 [CVE-2026-44745]
-
Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud (3763800): This Security Note addresses multiple known vulnerabilities in Apache Tomcat used by SAP Commerce Cloud. Remote unauthenticated attackers could exploit these vulnerabilities to bypass authentication, send crafted HTTP/2 requests, or bypass authorization rules, potentially resulting in a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 8,1/10 [CVE-2026-43512, CVE-2026-41293, CVE-2026-43515]
-
Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud (3763800): This Security Note addresses multiple known vulnerabilities in Apache Tomcat used by SAP Commerce Cloud. Remote unauthenticated attackers could exploit these vulnerabilities to bypass authentication, send crafted HTTP/2 requests, or bypass authorization rules, potentially resulting in a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 8,1/10 [CVE-2026-43512, CVE-2026-41293, CVE-2026-43515]
-
Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach) (3773304): SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application’s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system. CVSS v3 Base Score 7,6/10 [CVE-2026-58233]
Enlaces de referencia
Referencias, en inglés de SAP y Onapsis:
Recursos afectados
El listado completo de los sistemas/componentes afectados es el siguiente:
-
SAP NetWeaver Application Server ABAP: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20
-
SAP Approuter: SAP Approuter node.js package < 21.2.0
-
SAP Commerce Cloud: HY_COM 2205, COM_CLOUD 2211, 2211-JDK21
-
SAP NetWeaver Application Server Java (Web Container): ENGINEAPI 7.50
-
SAP Integration Suite (Edge Integration Cell): SAP Integration Suite (Edge Integration Cell) < 8.43.11
-
SAProuter on Microsoft Windows: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, SAP_ROUTER 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.17, 9.18
-
SAP NetWeaver Application Server Java(Configuration Wizard): LMCTC 7.50
-
SAP Change and Transport System Attach Tool (ctsattach): CTS_UPLOAD_CLT 1




