SAP Patches Critical Vulnerabilities in Business AI Platform
TL;DR. SAP has issued 30 security notes, including four for critical vulnerabilities impacting its enterprise software products. - The most severe flaw, CVE-2026-58231, in SAP Commerce Cloud, allows remote code execution without authentication. - Two critical code injection flaws in Manufacturing Integration and Intelligence could lead to full infrastructure compromise. - A memory corruption issue in Application Server ABAP could disclose sensitive data or crash systems. - An update also addressed a critical memory corruption bug in NetWeaver Application Server ABAP.
- SAP released 30 security notes, resolving 28 new and two updated vulnerabilities.
- Four critical vulnerabilities were addressed, including one with a CVSS score of 10/10.
- Flaws affect SAP Commerce Cloud, Manufacturing Integration and Intelligence, and Application Server ABAP.
- One high-severity flaw was noted in SAP's Business AI Platform (Approuter).
Sources
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities — securityweek.com