Tuesday, September 8, 2026

Severe SAP NetWeaver Vulnerability Allows Attackers to Bypass Authorization Checks

SAP has released nineteen security patches in its June Patch Day, addressing critical vulnerabilities that could allow attackers to bypass authorization controls and escalate privileges across multiple enterprise systems.

The update includes two HotNews Notes and seven High Priority Notes, with immediate action recommended for organizations running affected SAP environments.

The most severe vulnerability, tracked as SAP Security Note #3600840 with a CVSS score of 9.6, affects the Remote Function Call (RFC) framework in SAP NetWeaver Application Server AS ABAP.

This critical missing authorization check vulnerability enables authenticated attackers to bypass standard authorization controls on the S_RFC authorization object when using transactional (tRFC) or queued RFCs (qRFC).

Under specific conditions, attackers can exploit this vulnerability to achieve privilege escalation, critically impacting both application integrity and availability.

The vulnerability requires immediate kernel updates, with SAP warning that the patch may necessitate additional S_RFC permissions for some users.

Organizations can identify affected users and activate the additional authorization check by setting the profile parameter rfc/authCheckInPlayback to 1, as detailed in FAQ SAP Note #3601919.

SAP NetWeaver Vulnerability

Several high-priority vulnerabilities demand immediate attention across SAP’s business application portfolio.

SAP Security Note #3609271, rated 8.8 on the CVSS scale, addresses a vulnerability in SAP GRC that allows low-privileged users to initiate transactions capable of modifying or controlling transmitted system credentials.

Another significant vulnerability, covered by SAP Security Note #3606484 with a CVSS score of 8.5, involves a missing authorization check in SAP Business Warehouse and SAP Plug-In Basis.

This vulnerability enables unauthorized deletion of database tables through a remote-enabled function module without proper authorization verification.

Cross-site scripting vulnerabilities also feature prominently in this release.

SAP Security Note #3560693 patches an XSS vulnerability in SAP BusinessObjects Business Intelligence BI Workspace with a CVSS score of 8.2, where insufficient input sanitization allows unauthenticated attackers to inject malicious scripts that execute in victims’ browsers.

Comprehensive Patch Release

The Onapsis Research Labs played a significant role in identifying and helping remediate four vulnerabilities covered by two SAP Security Notes in this release.

Their contributions include discovering three vulnerabilities in SAP Master Data Management Server, addressed by SAP Security Note #3610006 with a CVSS score of 7.5.

These vulnerabilities include two memory corruption vulnerabilities that could trigger memory read access violations through specially crafted packets, potentially causing server process failures and impacting application availability.

Research also identified an insecure session management vulnerability allowing attackers to gain control of existing client sessions without re-authentication.

Additionally, the research team contributed to patching a cross-site scripting vulnerability in SAP NetWeaver AS ABAP’s keyword documentation, addressed by SAP Security Note #3590887 with a CVSS score of 5.8.

This vulnerability resulted from insufficient URL request validation, enabling unauthenticated attackers to inject malicious JavaScript through unprotected parameters.

Organizations should prioritize implementing these patches immediately, particularly the critical RFC framework vulnerability, to maintain security posture across their SAP environments.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Related Articles

Recent News