SAP warns of critical flaws in NetWeaver and Commerce Cloud

A trio of critical security vulnerabilities has been discovered in SAP’s NetWeaver and Commerce Cloud platforms, prompting the software giant to issue a warning to its customers. The flaws, which affect thousands of organizations worldwide, could allow attackers to gain unauthorized access to sensitive data, disrupt system availability, or even launch denial-of-service attacks.

At stake are some of the world’s largest companies, as SAP serves 99 out of the top 100 global corporations. The vulnerabilities were patched in SAP’s July security updates, which also addressed six high-severity flaws and numerous medium- and low-severity issues. While SAP has yet to detect any evidence of exploitation, the company’s products have been targeted by attackers in the past.

The first critical flaw affects NetWeaver Application Server ABAP, a runtime environment for core SAP enterprise software. An attacker with authenticated access could leverage memory management errors to cause corruption, leading to unauthorized data access or system unavailability. This vulnerability has significant implications for confidentiality, integrity, and availability of application data.

In addition to the NetWeaver flaw, two other critical vulnerabilities were identified in SAP Approuter and Commerce Cloud. The Approuter issue stems from a HTTP Request Smuggling weakness that can be exploited via specially crafted requests to access user responses or trigger denial-of-service attacks on the targeted system. Meanwhile, the Commerce Cloud flaw arises from default credentials that enable attackers to obtain valid access tokens and modify data through certain APIs.

These vulnerabilities are not isolated incidents; they come amid a growing trend of SAP products being targeted by attackers. CISA has added 14 SAP security flaws to its Known Exploited Vulnerabilities catalog since November 2021, including two exploited in ransomware attacks. In June, SAP patched 15 vulnerabilities as part of its Security Patch package, and the company’s official npm packages were compromised in a supply chain attack aimed at stealing developer credentials.

The warning serves as a reminder to organizations relying on SAP software to prioritize patching and testing their systems regularly. As security teams often struggle to detect threats before they cause harm, it is essential for companies to proactively test all layers of their environment – not just the most obvious ones. By doing so, they can ensure that their defenses are strong enough to withstand even the most sophisticated attacks.

Ultimately, the discovery of these vulnerabilities highlights the importance of staying vigilant in today’s threat landscape. Organizations must remain proactive and take a comprehensive approach to security testing, including using breach and attack simulation tools to validate their detection capabilities.


Source: Bleeping Computer — 2026-07-14