{"id":1763,"date":"2026-07-14T20:20:25","date_gmt":"2026-07-14T20:20:25","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1763"},"modified":"2026-07-14T20:20:25","modified_gmt":"2026-07-14T20:20:25","slug":"sap-patches-cvss-9-9-netweaver-abap-flaw-that-could-expose-or-modify-data","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1763","title":{"rendered":"SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 14, 2026<\/span><\/span><span class=\"p-tags\">Enterprise Security \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi9rN4ge3zuUmonccBl2yC_AcOKiCQPKQFAV31BzB3DZk3JO7SxAjx1HdJlg1vBOMEj3cq2Mrg06ZU64I1fdkWCDRBsPhqpuyJwTxjbJHJXmzUoXF8KRDkupk6JxznlI9tjMXwU_hJqh4InVEOsiknPoszVZkQsqWSKfcD5Y90qz63Cv_pOHL8zO4CxGOop\/s1700-e365\/sap-patch.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>SAP has rolled out updates to address <a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/july-2026.html\" target=\"_blank\">multiple vulnerabilities<\/a> as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-44747\" target=\"_blank\">CVE-2026-44747<\/a><\/strong> (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability.<\/p>\n<p>\u00abAs a temporary workaround the note proposes to disable all ICF nodes with a specific property in transaction SICF,\u00bb SAP security firm Onapsis <a href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-july-2026\/\" target=\"_blank\">said<\/a>. \u00abSince the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patching ABAP Kernel version.\u00bb<\/p>\n<p>Also addressed by SAP are two other critical vulnerabilities &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-27690\" target=\"_blank\">CVE-2026-27690<\/a><\/strong> (CVSS score: 9.1) &#8211; An HTTP request\/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments that allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization and results in the exposure of user responses and triggers denial-of-service (DoS) attacks.<\/li>\n<li><strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-44761\" target=\"_blank\">CVE-2026-44761<\/a><\/strong> (CVSS score: 9.1) &#8211; A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation.<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abIf left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data,\u00bb according to a description of CVE-2026-44761 in the NIST National Vulnerability Database (NVD). \u00abSuccessful exploitation results in high impact on confidentiality and integrity, with no impact on availability.\u00bb<\/p>\n<p>Onapsis noted that the vulnerability stems from sample configuration scripts previously provided in the SAP Help Portal. These scripts, originally meant for development and testing, configure OAuth 2.0 clients with hard-coded, well-known credentials.<\/p>\n<p>\u00abOlder versions of the documentation did not explicitly warn customers against importing these default settings into production,\u00bb it noted. \u00abAn unauthenticated attacker can leverage these publicly available, default credentials to obtain a valid access token. With this token, they can invoke specific APIs to read and alter system data. Exploitation requires that the customer executed the sample script and retained the resulting OAuth 2.0 client in production without replacing the hard-coded secret.\u00bb<\/p>\n<p>It&#8217;s worth noting that customers who removed the sample client or replaced the secret with a strong, unique value are not impacted by the bug. Customers are recommended to audit their production environments for the presence of the affected sample OAuth 2.0 client. If the client exists, it must be removed.<\/p>\n<p>Although there is no evidence of the flaws being exploited in the wild, it&#8217;s advised to apply the necessary updates for optimal protection.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 14, 2026Enterprise Security \/ Vulnerability SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1764,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2535,497,38,918,70,2536,2534,57,1231],"class_list":["post-1763","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abap","tag-cvss","tag-data","tag-expose","tag-flaw","tag-modify","tag-netweaver","tag-patches","tag-sap"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1763"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1763\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1764"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}