- Description
- Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
- Source
- cna@sap.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Severity
- CRITICAL
- cna@sap.com
- CWE-444
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-44761 ❗ CVE-2026-44747 ❗ CVE-2026-27690 ➡️ Más info: https://t.co/VxDSRqAJ34 https://t.co/6Fnqu3t1hg
@CERTpy
22 Jul 2026
197 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SAP、2026年7月のセキュリティパッチデーでCVSS 9.9のNetWeaver重大脆弱性を含む16件を修正(CVE-2026-44747, CVE-2026-27690) https://t.co/TICPuVyMS9 #セキュリティ対策Lab #security #securitynews
@securityLab_jp
16 Jul 2026
120 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 SAP's July 2026 Patch Day fixes 16 new security issues, led by a critical memory corruption flaw in NetWeaver AS ABAP (CVE-2026-44747, CVSS 9.9) affecting kernel versions 7.22 through 9.20 — both legacy and current deployments. ⚠️ A second critical bug (CVE-2026-27690
@techepages
14 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes