Skip to finding
important · Research — SAP

One Message Server packet can make an unauthenticated host trusted across an SAP cluster.

Affects

SAP NetWeaver Kernel infrastructure underlying ABAP-based SAP systems, including S/4HANA and ABAP Platform deployments.

A crafted packet to public port 36NN asserts trusted-node status, propagates that decision to application servers, and enables RFC-callable external programs to run as the SAP operating-system account.

Detail and 1 source
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026