<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — SAP</title><description>Vulnerabilities and patches across SAP&apos;s enterprise stack — NetWeaver Application Server (Java and ABAP), S/4HANA, Business Technology Platform, AppRouter, and Commerce Cloud — including the monthly SAP Security Patch Day cycle. Combined article + CVE feed for the SAP beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2010-5326 — SAP NetWeaver Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2010-5326/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-5326/</guid><description>SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2016-2386 — SAP NetWeaver SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2016-2386/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-2386/</guid><description>SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2016-2388 — SAP NetWeaver Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2016-2388/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-2388/</guid><description>The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>medium</category><category>cve</category></item><item><title>CVE-2016-3976 — SAP NetWeaver Directory Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3976/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3976/</guid><description>SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>high</category><category>cve</category></item><item><title>CVE-2016-9563 — SAP NetWeaver XML External Entity (XXE) Vulnerability</title><link>https://0daynews.com/cve/cve-2016-9563/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-9563/</guid><description>SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>medium</category><category>cve</category></item><item><title>CVE-2017-12637 — SAP NetWeaver Directory Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12637/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12637/</guid><description>SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>high</category><category>cve</category></item><item><title>CVE-2018-2380 — SAP Customer Relationship Management (CRM) Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2018-2380/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-2380/</guid><description>SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>medium</category><category>cve</category></item><item><title>CVE-2019-0344 — SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0344/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0344/</guid><description>SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-6207 — SAP Solution Manager Missing Authentication for Critical Function Vulnerability</title><link>https://0daynews.com/cve/cve-2020-6207/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-6207/</guid><description>SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-6287 — SAP NetWeaver Missing Authentication for Critical Function Vulnerability</title><link>https://0daynews.com/cve/cve-2020-6287/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-6287/</guid><description>SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-38163 — SAP NetWeaver Unrestricted File Upload Vulnerability</title><link>https://0daynews.com/cve/cve-2021-38163/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-38163/</guid><description>SAP NetWeaver contains a vulnerability that allows unrestricted file upload.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-22536 — SAP Multiple Products HTTP Request Smuggling Vulnerability</title><link>https://0daynews.com/cve/cve-2022-22536/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-22536/</guid><description>SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim&apos;s request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-31324 — SAP NetWeaver Unrestricted File Upload Vulnerability</title><link>https://0daynews.com/cve/cve-2025-31324/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-31324/</guid><description>SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-42999 — SAP NetWeaver Deserialization Vulnerability</title><link>https://0daynews.com/cve/cve-2025-42999/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-42999/</guid><description>SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-27690 — SAP AppRouter HTTP request smuggling in Node.js middleware</title><link>https://0daynews.com/cve/cve-2026-27690/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-27690/</guid><description>Unauthenticated HTTP request smuggling in SAP AppRouter — the Node.js middleware fronting Business Technology Platform. NVD scored it 9.1. A crafted request can desynchronize the request-response pipeline, exposing other users&apos; responses and knocking the service offline.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-44747 — SAP NetWeaver AS ABAP memory-corruption via logical errors in memory management</title><link>https://0daynews.com/cve/cve-2026-44747/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-44747/</guid><description>Authenticated memory-corruption in NetWeaver Application Server ABAP that NVD scored 9.9 — a logged-in attacker can leverage logical errors in memory management to read data, modify data, or take the application down. Fixed in the SAP July 2026 Security Patch Day.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-44761 — SAP Commerce Cloud ships sample OAuth2 client with publicly documented credentials</title><link>https://0daynews.com/cve/cve-2026-44761/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-44761/</guid><description>SAP Commerce Cloud retained a sample OAuth2 client whose credentials were documented in SAP Help Portal. If left unchanged, an unauthenticated attacker can use those well-known values to obtain a valid access token and read or modify tenant data via certain APIs. NVD scored 9.1.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-58231 — SAP Commerce Cloud Data Hub Adapter Unauthenticated RCE</title><link>https://0daynews.com/cve/cve-2026-58231/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-58231/</guid><description>Insufficient authorization checks and input validation in SAP Commerce Cloud Data Hub Adapter allow unauthenticated remote code execution. CVSS 10.0.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>SAP</category><category>critical</category><category>cve</category></item><item><title>SAP Commerce Cloud RCE Exploit Hits Days After Patch</title><link>https://0daynews.com/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/</guid><description>Defused flagged active exploitation of a max-severity SAP Commerce Cloud RCE within 72 hours of patching. Unpatched instances are live targets now.</description><pubDate>Fri, 14 Aug 2026 16:30:00 GMT</pubDate><category>SAP</category><category>article</category></item><item><title>SAP Commerce Cloud CVSS 10 RCE — Patch Released</title><link>https://0daynews.com/articles/2026-08-12-sap-commerce-cloud-cve-2026-58231-cvss10-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-sap-commerce-cloud-cve-2026-58231-cvss10-rce/</guid><description>SAP patches CVE-2026-58231, a CVSS 10.0 unauthenticated RCE in Commerce Cloud&apos;s Data Hub Adapter. Apply the fix now or take the component offline.</description><pubDate>Wed, 12 Aug 2026 10:00:00 GMT</pubDate><category>SAP</category><category>article</category></item><item><title>SAP&apos;s July Patch Day: three criticals, worst is 9.9</title><link>https://0daynews.com/articles/2026-07-14-sap-july-patch-day-three-criticals-netweaver-approuter-commerce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-sap-july-patch-day-three-criticals-netweaver-approuter-commerce/</guid><description>SAP&apos;s July 2026 Security Patch Day fixes 16 flaws — three rated critical, worst a CVSS 9.9 memory-corruption bug in NetWeaver ABAP. No known exploitation yet.</description><pubDate>Tue, 14 Jul 2026 13:15:00 GMT</pubDate><category>SAP</category><category>article</category></item></channel></rss>