Skip to content

Product1 publisher2 min readPublished

SAP patches a kernel flaw that lets unauthenticated requests run OS commands as SAP admin

Onapsis, which found the flaw alongside SAP, rates it CVSS 10.0 and recommends immediate patching. A second kernel note in the same batch reaches every S/4HANA 2025 system and any older release already on a current kernel.

The Product Desk · Product desk

Photograph accompanying SAP patches a kernel flaw that lets unauthenticated requests run OS commands as SAP admin
Photo: thehackernews.com

What happened

  • Note 3747649, scored CVSS 10.0, patches a memory corruption vulnerability in SAP Extended Passport processing that the Onapsis Research Labs has named OVERPASS.
  • Onapsis says the flaw lets remote attackers run arbitrary operating system commands on the SAP host with SAP administrative privileges, fully compromising the business data and processes underneath.
  • The fix ships for the ABAP and Java kernels and for SAP Web Dispatcher 9.16, while other Web Dispatcher versions and the one inside SAP HANA Extended Application Services are unaffected.
  • A second note, 3759472 at CVSS 9.8, covers the SAP NetWeaver Message Server and carries the vulnerability Onapsis calls S4GET.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The patch is the mitigation here, so for teams whose kernel updates are quarterly the calendar is the hard part.
  • decision S/4HANA 2025 operators cannot scope their way out of S4GET, so what they are deciding is the order in which landscapes take the kernel update.
  • exposure Because exploitation needs no credentials, the threat model widens past people with SAP accounts to anyone who can reach one of the affected protocols.

The people this lands on booked their next kernel window months ago. OVERPASS sits in SAP Extended Passport processing, where Onapsis says boundary validation is missing during deserialization of EPP data, so the code hits a memory safety violation when it processes externally supplied length fields [5]. An unauthenticated attacker sends a crafted network request carrying a malformed EPP header, and the program runs into undefined behavior and terminates abnormally [6].

The usual answer to a critical note landing between windows is to block something at the edge and wait. Onapsis wrote that the flaw "is reachable through several SAP components and several communication protocols, none of them requiring credentials, so no single network control can fully mitigate risk" [10]. The firm recommends immediate patching, and gives the default presence of the affected code across a wide range of SAP technology components as part of the reason [8].

S4GET is a different sort of problem to plan. The NetWeaver Message Server, according to Onapsis, does not sufficiently validate the authenticity of internal application server components during registration, so unauthenticated attackers with network access can register unauthorized components and perform unauthorized actions inside the application environment [12]. The flaw is present across the four kernels of SAP's modern family: 9.16, 9.18, 9.19 and 9.20 [13][17].

Half of September's list carries one of the top two ratings, five HotNews and six High Priority out of 22 new and updated notes [1][16]. Onapsis says its own contribution was eight vulnerabilities covered by six notes, three of them HotNews [2]. The post's counts do not quite line up: it gives twenty-two new and updated notes in the summary, then refers to six of the twenty new notes a paragraph later [1][3]. It names CVE-2026-44756 and CVE-2026-58240 as the month's critical CVEs without saying which note carries which [15].

The two things that sort this queue are whether exploitation needs credentials, and whether a control already running takes the risk to zero before the patch is installed. OVERPASS fails both [8][10]. The month's other 10.0 goes the other way. Note 3771065 updates an SAP Commerce Cloud Data Hub Adapter note first released on August's patch day to say that unmodified environments are not exposed by default, and it points administrators to an FAQ document for verifying their setup [14].

What to watch

  • Whether a later revision of note 3747649 extends the OVERPASS patch beyond SAP Web Dispatcher 9.16.
  • Whether exploit code for OVERPASS surfaces publicly, given Onapsis says it needs no credentials and is reachable over several protocols.
  • Whether October's patch day revises the S4GET kernel list, which would reopen scoping for shops that have already patched.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories