Skip to finding
important · Edge devices

Public SAPMAP code now automates S4GET's pre-authentication takeover path across SAP application-server clusters.

Affects

SAP NetWeaver Message Server and Gateway infrastructure used by SAP S/4HANA, S/4HANA Cloud Private Edition, ABAP Platform, and other ABAP-based systems on affected kernel lines.

From Message Server port 36NN, a crafted registration makes the attacker's IP trusted across the cluster; SAP Gateway then accepts external-program invocation from that address and executes as the SAP operating-system account. A patch is available.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026