SAP Releases Patches for Security Flaws Allowing Remote Code Execution
ID: 297b99db-cb2a-54d1-a605-20748ad2a28c
STIX ID: report--297b99db-cb2a-54d1-a605-20748ad2a28c
Feed Name: GBHackers
SAP's March 10, 2026 Security Patch Day released 15 new security notes addressing critical to low-severity vulnerabilities across its enterprise products; the most severe is an unauthenticated code injection RCE in SAP Quotation Management (CVE-2019-17571, CVSS 9.8), with other high-impact fixes including an insecure deserialization in NetWeaver Enterprise Portal (CVE-2026-27685, CVSS 9.1) and a DoS in Supply Chain Management (CVE-2026-27689, CVSS 7.7). Multiple medium-severity issues (SSRF, SQLi, DOM XSS, missing authorization checks) were also patched; administrators are urged to review the SAP Support Portal for details and apply updates immediately to prevent potential full system compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
