Skip to finding
important · Edge — SAP Cluster

An unauthenticated SAP Message Server caller can become a trusted cluster node and execute code across every application server.

Affects

SAP NetWeaver Message Server on ABAP systems using affected 9.x kernels, including S/4HANA and S/4HANA Cloud Private Edition deployments.

A crafted registration packet sent to public port 36NN makes the Message Server trust an attacker-controlled address as an internal application-server component.

Detail and 2 sources

That trust propagates across the cluster, allowing the attacker to reach SAP Gateways, invoke RFC-callable external programs and execute commands as the SAP operating-system administrator.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026