important · Research — SAP
One Message Server packet can make an unauthenticated host trusted across an SAP cluster.
Affects
SAP NetWeaver Kernel infrastructure underlying ABAP-based SAP systems, including S/4HANA and ABAP Platform deployments.
A crafted packet to public port 36NN asserts trusted-node status, propagates that decision to application servers, and enables RFC-callable external programs to run as the SAP operating-system account.
Detail and 1 source
SAP published remediated patch levels in Security Note 3759472.