Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory
2026/08/11 CyberSecurityNews — SAP の 2026年8月 Security Patch Day で提供されたのは、28 件の新規セキュリティ・ノートと 1 件の GitHub セキュリティ・アドバイザリへの対応に加え、以前にリリースされた 2 件のノートの更新も含む、かなり大規模な修正である。この 2026年8月11日にリリースされたパッチ群は、広く展開されているエンタープライズ・プラットフォーム全体に及ぶものであり、未認証の攻撃者によるコード注入/メモリ破損/権限昇格を可能にし得る、複数の重大な深刻度の欠陥に対処するものである。

エンタープライズ・リソース・プランニング/金融/サプライチェーン/コマース運用において、広範な企業が SAP システムに依存している。セキュリティ・チームに対して強く推奨されるのは、このアップデート・サイクルを緊急優先事項として扱うことである。
深刻な SAP 脆弱性が悪意のあるコード・インジェクションを可能にする
今月の Security Patch Day で最も警戒すべき脆弱性は、SAP Commerce Cloud の Data Hub Adapter に存在する不適切な認可処理の脆弱性であり、CVE-2026-58231 (CVSS:10.0) は、COM_CLOUD バージョン 2211/2211-JDK21 に影響を及ぼす。この脆弱性の悪用には事前の権限やユーザー操作が不要であり、リモート攻撃者が機密性/完全性/可用性を完全に制御できる可能性がある。
それに続くのが、SAP Manufacturing Integration and Intelligence に存在する重大なコード注入脆弱性 CVE-2026-44772 (CVSS:9.9) である。この脆弱性は XMII および MII_ADMIN バージョン 15.4/15.5 に影響を及ぼし、悪用に成功した攻撃者に対して、本番環境の重要なソフトウェア上で任意のコードを実行することを許す。同じコンポーネントに存在する 2 件目のコード注入脆弱性 CVE-2026-44758 (CVSS:9.1) も、Critical と評価されている。
このリリース・サイクルでは、メモリ破損のリスクも目立っている。脆弱性 CVE-2026-34265 (CVSS:9.8) は、SAP NetWeaver および ABAP Platform 内の Application Server ABAP コンポーネントに影響を及ぼす、深刻なメモリ破損の脆弱性である。この脆弱性は、バージョン 7.22 〜 9.19 の幅広いカーネル・バージョンに影響を及ぼす。
コア・アプリケーション・サーバーにおけるメモリ破損の脆弱性は、きわめて危険である。これらの脆弱性を悪用する攻撃者は、リモート・コード実行を達成して初期アクセスを確立し、企業ネットワーク全体への横展開のための足掛かりを得る恐れがある。このようなシステム全体に関わるメモリ問題を緩和するためには、脅威アクターが信頼性の高い攻撃手順を構築する前に、深刻な SAP の脆弱性に対するパッチを適用する必要がある。
SAP の 2026年8月セキュリティ・パッチ・デー公式アドバイザリで概説されているように、この種のエンタープライズ・システムは、高度な脅威グループから継続的に標的にされている。これらのパッチを適用することで、敵対者による未パッチ・インフラの武器化や、コア・ビジネス・データベースに対する SQL インジェクションの脆弱性の悪用を阻止する必要がある。
| SAP Note / Advisory | CVE | Vulnerability | Affected Product | CVSS |
|---|---|---|---|---|
| 3771065 | CVE-2026-58231 | Improper authorization | SAP Commerce Cloud (Data Hub Adapter), COM_CLOUD 2211 / 2211-JDK21 | 10.0 |
| 3765948 | CVE-2026-44772 | Code injection | SAP Manufacturing Integration and Intelligence; XMII and MII_ADMIN 15.4 / 15.5 | 9.9 |
| 3714806 | CVE-2026-34265 | Memory corruption | SAP NetWeaver and ABAP Platform; affected kernel versions 7.22–9.19 | 9.8 |
| 3758900 | CVE-2026-44758 | Code injection | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 9.1 |
| 3772411 | CVE-2026-58243 | Privilege escalation | SAP ABAP Developer Tools; SAP_BASIS 750–758, 816, 918, 920 | 8.8 |
| 3773203 | CVE-2026-42945 | Potential buffer overflow | SAP Commerce Cloud public-cloud deployments with NGINX | 8.1 |
| 3756565 | CVE-2026-66763 | Credentials disclosure | SAP BusinessObjects BI Platform (Central Management Server) | 7.9 |
| 3727078 | CVE-2026-58233 | Remote code execution; updated July 2026 note | SAP Change and Transport System Attach Tool (ctsattach), CTS_UPLOAD_CLT 1 | 7.6 |
| 3759854 | CVE-2026-44763 | Directory traversal | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.6 |
| 3758657 | CVE-2026-44765 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.3 |
| 3758910 | CVE-2026-44764 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.3 |
| 3786038 | CVE-2026-58230 and 10 related CVEs | Multiple vulnerabilities | SAP Business AI Platform (Approuter), versions earlier than 23.0.0 | 7.0 |
| 3753141 | CVE-2026-58248 | XML external entity injection | SAP BusinessObjects Business Intelligence | 6.5 |
| 3770868 | CVE-2026-34480 | Improper output encoding in Apache Log4j Core | SAP Commerce Cloud and SAP Data Hub | 6.5 |
| 3757815 | CVE-2026-5598 | Potential information disclosure in Bouncy Castle Java library | SAP Commerce Cloud | 6.5 |
| 3721424 | CVE-2026-66779 | Cross-site scripting | SAP NetWeaver Application Server ABAP | 6.3 |
| 3766473 | CVE-2026-66770 | SQL injection | SAP Social Intelligence; S4FND 102–109 | 6.3 |
| 3758318 | CVE-2026-58235 | Vulnerable third-party component | SAP NetWeaver AS Java (Adobe Document Services) | 6.3 |
| 3772071 | CVE-2026-66771 | Cross-site scripting | SAPUI5 | 6.1 |
| GHSA-hc5j-q32w-c25v | CVE-2026-66773 | Server-controlled __next URL lacks cross-origin validation | pyodata Python package, versions earlier than 1.11.2 | 5.9 |
| 3745182 | CVE-2026-58236 | OS command injection | SAP NetWeaver Application Server ABAP and ABAP Platform | 5.5 |
| 3540688 | CVE-2025-42947 | Code injection; updated July 2025 note | SAP FICA ODN Framework | 5.5 |
| 3725940 | CVE-2026-40130 | Memory corruption | SAPSPrint Service, SAPSPRINT 8.00 / 8.10 | 5.3 |
| 3756674 | CVE-2026-58247 | Memory corruption | SAP ABAP Platform; selected kernel 7.53–7.77 versions | 5.3 |
| 3778462 | CVE-2026-33871, CVE-2025-58057 | Multiple vulnerabilities | SAP Commerce Cloud Search and Navigation | 4.8 |
| 3669608 | CVE-2026-66764 | Missing authorization check | SAP S/4HANA Reprocess Bank Statement Items | 4.3 |
| 3770649 | CVE-2026-66772 | Missing authorization check | SAP BusinessObjects BI Platform Admin Tools; also listed for S/4HANA | 4.3 |
| 3781137 | CVE-2026-58244 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 4.3 |
| 3752864 | CVE-2026-58241 | Missing authorization check | SAP NetWeaver and ABAP Platform Change and Transport System wizard | 4.2 |
| 3763028 | CVE-2026-58245 | Hard-coded credentials | SAP Advanced Planning and Optimization Model Mix Planning | 3.8 |
| 3739913 | CVE-2026-44762 | Security misconfiguration | SAP Data Services Management Console | 3.7 |
重大 (Critical) と評価された脆弱性以外にも、複数の高深刻度の問題が存在するため、これらについても直ちに修正する必要がある。
- 権限昇格 (CVE-2026-58243): スコアは 8.8 であり、SAP ABAP Developer Tools 内の幅広い SAP_BASIS バージョンに影響する。
- パブリック・クラウドにおけるバッファー・オーバーフロー (CVE-2026-42945): スコアは 8.1 であり、パブリック・クラウド・コンフィグで NGINX を実行している SAP Commerce Cloud 環境に影響する。
- CTS Attach Tool におけるリモート・コード実行 (CVE-2026-58233): 2026年7月に開示された、Change and Transport System Attach Tool (ctsattach) に存在するリモート・コード実行の脆弱性に関する更新情報である。
- 追加の高深刻度ノート: SAP BusinessObjects Business Intelligence Platform における認証情報の開示や、Manufacturing Integration and Intelligence におけるディレクトリ・トラバーサルと認可チェックの欠如を対象とする。
中程度/低程度の脆弱性に関するノートでは、各種モジュールに存在する幅広い欠陥も対処されている。具体的には、SAPUI5 および NetWeaver Application Server ABAP におけるクロスサイト・スクリプティング (XSS)/SAP Social Intelligence における SQL インジェクション/BusinessObjects における XML 外部実体 (XXE) 注入/pyodata ライブラリの脆弱性 (GHSA-hc5j-q32w-c25v)/Commerce Cloud が利用する Bouncy Castle Java ライブラリの情報漏洩の脆弱性などが含まれる。
これらの脆弱性の影響は、NetWeaver/ABAP Platform/Commerce Cloud/BusinessObjects/Manufacturing Integration and Intelligence を含む製品群に広く影響が及んでいるため、セキュリティ管理者にとって必要なことは、これらの SAP セキュリティ・アップデートの適用を優先することである。以下の手順が推奨される。
- 露出しているインスタンスの特定: Commerce Cloud/NetWeaver/MII を実行している、公開向けおよび内部向けのすべての SAP 展開環境を洗い出す。
- 重大なノートを優先: CVE-2026-58231/CVE-2026-44772/CVE-2026-34265 に対するパッチを、緊急メンテナンス・スケジュールで適用する。
- 開発者ツールの監査: 開発環境における権限昇格リスクを解消するために、SAP_BASIS モジュールを更新する。
- サードパーティ・ライブラリの検証: pyodata や Bouncy Castle のような基盤となる依存ライブラリが、カスタム・アプリケーション拡張全体で更新されていることを確認する。
SAP セキュリティ・パッチ・デーで公開された、複数の脆弱性を解説する記事です。基幹業務システムや製造管理の分野で広く活用されている SAP Commerce Cloud や SAP Manufacturing Integration and Intelligence、 SAP NetWeaver などの基底システムに深刻な欠陥が確認されました。認可処理の不足やコード注入/メモリ破損などの影響で、外部から任意のプログラムを動かされたり基幹ネットワークの制御権を奪われる危険性があります。対象プログラムの洗い出し/緊急での修正プログラムの適用/依存するサードパーティ製ライブラリの更新、といった迅速なセキュリティ対策が求められます。
You must be logged in to post a comment.