Executive Summary
On 11 August 2026, SAP released 28 new Security Notes, 1 GitHub Security Advisory, and 2 updates to previously released Security Notes. Across the complete August overview, this results in 31 items: 5 Critical entries, 7 High-priority items, 17 Medium-priority items, and 2 Low-priority items. Four of the Critical entries are new this month; the fifth is an updated NetWeaver AS Java directory traversal note originally released in June.
August is one of the broader SAP security releases of the year. The highest-risk issues include an unauthenticated CVSS 10.0 compromise path in SAP Commerce Cloud, two critical code-injection weaknesses in SAP Manufacturing Integration and Intelligence (MII), and unauthenticated memory corruption in the ABAP DIAG protocol path. The High-priority set also reaches into ABAP Developer Tools, BusinessObjects, Commerce Cloud infrastructure, MII, and SAP Approuter. The practical message for defenders is clear: this is not a single-platform patch cycle. Basis, manufacturing/OT, commerce, development, cloud, and BI owners all have work to do.
Patch Day Overview
| Priority | Count | Notes / Items |
|---|---|---|
| Critical | 5 | 3771065, 3765948, 3714806, 3758900, 3727078 (updated) |
| High | 7 | 3772411, 3773203, 3756565, 3759854, 3758657, 3758910, 3786038 |
| Medium | 17 | 15 new SAP Notes + GHSA-hc5j-q32w-c25v + 3540688 (updated) |
| Low | 2 | 3763028, 3739913 |
| Total items | 31 | 28 new SAP Notes + 1 GitHub advisory + 2 updated SAP Notes |
Key Takeaways
- SAP Security Note 3771065 is the first patch priority for affected Commerce Cloud environments. The Data Hub Adapter issue is remotely reachable without authentication and can lead to arbitrary code execution. SAP provides fixed Commerce Cloud releases and an IP-filter workaround for the affected import endpoint if immediate deployment is not possible.
- Manufacturing Integration and Intelligence is the dominant risk cluster this month. Six August notes affect MII, including two Critical code-injection issues, three High-severity path or authorization flaws, and one Medium authorization issue. Manufacturing customers should treat the MII set as a coordinated remediation program rather than isolated notes.
- SAP Security Note 3714806 affects a core ABAP protocol path. An unauthenticated attacker can trigger memory corruption through malformed DIAG protocol data. There is no workaround; remediation depends on the corrected SAP kernel.
- ABAP Developer Tools deserves unusual attention this month. Note 3772411 shows how a low-privileged developer account can abuse SQL Console behavior to perform unauthorized database operations. Review developer authorizations as part of the patch, not only the software level.
- Cloud-edge configuration remains part of patch management. The Approuter update in Note 3786038 addresses multiple security classes at once and requires an upgrade to @sap/approuter 23.0.0 or later, while several scenarios remain configuration-dependent.
- Some August fixes require operational follow-through after the binary patch. Commerce Cloud may require rebuild and redeploy, MII requires secure XSL transformation settings, and BusinessObjects environments with pre-existing secondary credentials may require cryptographic key rotation and credential recoding.
Complete August 2026 Inventory
The table below reflects the full August Patch Day overview used for this analysis. It includes all 28 new SAP Security Notes, the GitHub Security Advisory listed by SAP, and both notes SAP marked as updates to prior releases.
| Note / Advisory | Title | Priority | Status | CVSS |
|---|---|---|---|---|
| 3771065 | Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) | Critical | New | 10.0 |
| 3765948 | Code Injection vulnerability in SAP Manufacturing Integration and Intelligence | Critical | New | 9.9 |
| 3714806 | Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform | Critical | New | 9.8 |
| 3758900 | Code Injection vulnerability in Manufacturing Integration and Intelligence | Critical | New | 9.1 |
| 3727078 | Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) | Critical | Updated | 9.0 |
| 3772411 | Privilege Escalation vulnerability in SAP ABAP Developer Tools | High | New | 8.8 |
| 3773203 | Potential buffer overflow vulnerability in SAP Commerce Cloud public-cloud deployments with NGINX | High | New | 8.1 |
| 3756565 | Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) | High | New | 7.9 |
| 3759854 | Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence | High | New | 7.6 |
| 3758657 | Missing Authorization Check in SAP Manufacturing Integration and Intelligence | High | New | 7.3 |
| 3758910 | Missing Authorization Check in SAP Manufacturing Integration and Intelligence | High | New | 7.3 |
| 3786038 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) | High | New | 7.0 |
| 3770868 | Improper Output Encoding vulnerability in SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core) | Medium | New | 6.5 |
| 3757815 | Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library) | Medium | New | 6.5 |
| 3753141 | XML External Entity Injection in SAP BusinessObjects Business Intelligence | Medium | New | 6.5 |
| 3758318 | Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) | Medium | New | 6.3 |
| 3766473 | SQL Injection vulnerability in SAP Social Intelligence | Medium | New | 6.3 |
| 3721424 | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP | Medium | New | 6.3 |
| 3772071 | Cross Site Scripting (XSS) vulnerability in SAPUI5 | Medium | New | 6.1 |
| GHSA-hc5j-q32w-c25v | Server-controlled __next URL is not checking cross-origin in pyodata | Medium | Advisory | 5.9 |
| 3745182 | OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform | Medium | New | 5.5 |
| 3540688 | Code Injection vulnerability in SAP FICA ODN framework | Medium | Updated | 5.5 |
| 3725940 | Memory Corruption vulnerability in SAPSPrint Service | Medium | New | 5.3 |
| 3756674 | Memory Corruption vulnerability in SAP ABAP Platform | Medium | New | 5.3 |
| 3778462 | Multiple vulnerabilities in SAP Commerce Cloud (Search and Navigation) | Medium | New | 4.8 |
| 3770649 | Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools) | Medium | New | 4.3 |
| 3669608 | Missing Authorization check in SAP S/4HANA (Reprocess Bank Statement Items) | Medium | New | 4.3 |
| 3781137 | Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII) | Medium | New | 4.3 |
| 3752864 | Missing Authorization Check in SAP NetWeaver and ABAP Platform (Customer Transport Integration Wizard) | Medium | New | 4.2 |
| 3763028 | Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning) | Low | New | 3.8 |
| 3739913 | Security Misconfiguration in SAP Data Services Management Console | Low | New | 3.7 |
Critical & High-Priority Security Notes
The following issues deserve the fastest review because they provide direct compromise paths, affect core SAP platform components, or expose functionality that is commonly reachable in enterprise landscapes. Where exploitation depends on privileges or non-default configuration, that distinction is called out explicitly.
3771065 — Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) — CVSS 10.0, Critical
What Is Affected: SAP Commerce Cloud deployments using the Data Hub Adapter extension, specifically the Data Hub import path. Commerce Cloud is commonly customer- or partner-facing, while the affected adapter endpoint is intended for Data Hub server communication and should not be broadly reachable.
Nature of the Vulnerability: The affected functionality combines insufficient authorization checks with unsafe handling of attacker-controlled input. An unauthenticated remote attacker can abuse a default authentication client and submit crafted data to functions that do not sufficiently validate it. In the vulnerable path, that can progress to arbitrary code execution and compromise internal application components.
Attack Scenarios: No valid user account is required. The realistic attack path is direct network access to an affected Commerce Cloud instance with the Data Hub Adapter enabled, followed by crafted requests to the import endpoint. Successful exploitation can give an attacker execution capability inside a trusted commerce application tier and create a platform for lateral movement.
Business Impact: The technical impact is complete confidentiality, integrity, and availability compromise. In business terms, a successful attack can expose customer and order data, manipulate application behavior, interrupt storefront or integration flows, and compromise credentials or services trusted by the Commerce environment.
Mitigation and Recommendations: Upgrade to SAP Commerce Cloud 2211.55, 2211-jdk21.17, or a later fixed release, then rebuild and redeploy the application. If patching cannot be completed immediately, SAP documents an IP Filter Set workaround for /datahubadapter/import/** that permits only known Data Hub egress addresses. Treat that filter only as a temporary reduction in attack surface.
3765948 — Code Injection in SAP Manufacturing Integration and Intelligence — CVSS 9.9, Critical
What Is Affected: SAP Manufacturing Integration and Intelligence (MII), particularly XSL transformation functionality. MII is frequently deployed close to manufacturing execution, plant integration, historian, quality, and shop-floor systems, making it a high-value bridge between enterprise IT and operational technology.
Nature of the Vulnerability: The issue originates in server-side request forgery during XSL transformation processing. A low-privileged user can cause the application to retrieve and process attacker-controlled external content. The vulnerable transformation path can then be abused to execute arbitrary commands on the underlying host.
Attack Scenarios: The attacker requires an authenticated but low-privileged account and network reachability to MII. A plausible scenario is a compromised user or technical account pointing the XSL processing path at attacker-controlled content and using the resulting transformation behavior to execute operating-system commands. No victim interaction is required.
Business Impact: Host-level command execution on an MII server can move an incident from application abuse into manufacturing operations. An attacker may gain access to sensitive production data, modify integration logic or files, disrupt plant-facing services, and pivot into systems that implicitly trust the MII host.
Mitigation and Recommendations: Implement the support packages and patches referenced by SAP. After patching, enable the new Secure Transformer system property and configure the Allowed Hosts list for legitimate XSL locations. SAP states that there is no workaround, so organizations should not rely on segmentation alone as a substitute for the correction.
3714806 — Memory Corruption in Application Server ABAP for SAP NetWeaver and ABAP Platform — CVSS 9.8, Critical
What Is Affected: SAP NetWeaver Application Server ABAP and ABAP Platform kernel processing associated with the DIAG protocol. This is a core communication path in classic SAP environments and therefore has a much broader deployment footprint than many application-specific notes.
Nature of the Vulnerability: Improper validation of boundary conditions in DIAG protocol parsing can lead to memory corruption. SAP describes potential disclosure of sensitive information and system crashes; the note also classifies the issue among memory-corruption and remote-code-execution risk terms. Because the flaw sits in low-level protocol handling, defenders should treat it as a core platform issue rather than an application defect.
Attack Scenarios: The attacker does not require authentication. A crafted DIAG protocol request reaching the vulnerable kernel path can trigger the memory-safety condition. The exact outcome can depend on runtime state and platform protections, but the lack of an authentication prerequisite makes exposed or broadly reachable SAP dispatcher paths particularly important to assess.
Business Impact: A successful attack can undermine the reliability and trust boundary of the ABAP application server itself. Even where exploitation results only in memory disclosure or a crash, the impact can include sensitive data exposure, loss of service, and disruption to multiple business applications sharing the same ABAP platform.
Mitigation and Recommendations: Apply the corrected SAP kernel patch level referenced in the note. SAP provides the correction through kernel archives and recommends following its normal kernel patch strategy, including regression review and use of a downward-compatible kernel where required. There is no workaround.
3758900 — Code Injection in SAP Manufacturing Integration and Intelligence — CVSS 9.1, Critical
What Is Affected: SAP MII deployments that use the IllumXSLTServlet for XSL transformations. The exposure is narrower than Note 3765948 because exploitation requires access to the XMII_IllumXSLTServlet action and an implementation that actually uses the affected servlet.
Nature of the Vulnerability: The IllumXSLTServlet processes attacker-controlled transformation input without sufficient validation. SAP describes the issue as code injection and references server-side template injection, SSRF, and remote code execution as relevant attack classes. Successful exploitation can result in arbitrary operating-system command execution.
Attack Scenarios: The attacker needs high privileges or equivalent access to the affected servlet action. This makes the most realistic threat model a compromised developer or administrator account, malicious insider activity, or post-compromise privilege abuse rather than anonymous internet exploitation.
Business Impact: MII often connects directly to manufacturing data, production systems, and plant integrations. Host-level command execution can therefore expose not only the MII application but also credentials, files, and trusted downstream connections with direct operational relevance.
Mitigation and Recommendations: Implement the referenced MII patches. SAP removes the vulnerable servlet and directs implementations to use the XSL Transform action block instead. Until the patch is applied, do not assign the XMII_IllumXSLTServlet action to roles and migrate any service dependency away from the servlet. SAP explicitly frames this as a temporary workaround, not a permanent fix.
3727078 — Updated: Directory Traversal in SAP NetWeaver Application Server Java (Web Container) — CVSS 9.0, Critical
What Is Affected: SAP NetWeaver Application Server Java Web Container, ENGINEAPI 7.50. SAP re-released this note in the August overview after its original June 2026 publication, so customers that already processed the earlier version should re-check the current correction guidance and applicability.
Nature of the Vulnerability: The underlying issue is insufficient path validation in the Java Web Container. A crafted request can manipulate file-related processing so that operations escape the intended directory or context, creating a path to unauthorized access or modification of local resources.
Attack Scenarios: The vulnerability is remotely reachable without prior authentication, although SAP rates attack complexity as high. That makes the primary concern any affected Java web container reachable from untrusted networks or large internal user populations.
Business Impact: Directory traversal at the application-server layer can expose configuration or application files, enable unauthorized file access or modification, and destabilize services. The risk is especially relevant in long-lived NetWeaver Java landscapes that may sit behind legacy portals or integrations.
Mitigation and Recommendations: Use the latest version of SAP Security Note 3727078 and apply the current support packages or patches referenced by SAP. Because this is an updated note, confirm that previous change records did not close the item based on an earlier revision alone.
3772411 — Privilege Escalation in SAP ABAP Developer Tools — CVSS 8.8, High
What Is Affected: SAP ABAP Development Tools (ADT), specifically SQL Console behavior against SAP NetWeaver AS ABAP. ADT is widely used by ABAP developers and technical teams, and developer users often hold more privileges than ordinary business users.
Nature of the Vulnerability: The SQL Console permitted host expressions in a way that bypassed the intended scope of the tool. A low-privileged user could use this behavior to perform database operations that should not be available through their assigned access level, undermining authorization boundaries at the data layer.
Attack Scenarios: An attacker needs an authenticated low-privileged account with access to the affected ADT functionality. In practice, a compromised developer credential could be used to read sensitive data, modify application data, or interfere with access for legitimate users without first obtaining a full administrator role.
Business Impact: This is a strong example of why developer tooling belongs in SAP security governance. Unauthorized database operations can compromise business data directly and may bypass controls that teams expect to be enforced through application transactions or APIs.
Mitigation and Recommendations: Apply the referenced support packages and patches. As a temporary mitigation, SAP recommends ensuring that S_TABU_NAM and S_TABU_DIS are not assigned to users who should not have table access through generic tools. Review ADT users and developer roles as part of the remediation.
3773203 — Potential Buffer Overflow in SAP Commerce Cloud Public-Cloud Deployments with NGINX — CVSS 8.1, High
What Is Affected: SAP Commerce Cloud public-cloud environments hosting JavaScript storefronts through affected NGINX Open Source components. Commerce storefront infrastructure is normally internet-facing, but SAP notes that exploitation requires specific conditions and memory-protection bypasses.
Nature of the Vulnerability: The bundled NGINX version contains a buffer-overflow condition that can be triggered by specially crafted network requests. Successful exploitation could corrupt memory in an internal process and, if environmental conditions align, lead to arbitrary code execution.
Attack Scenarios: No authentication is required, but SAP rates attack complexity as high. This is not a simple one-request compromise in every environment. The practical risk rises for publicly reachable storefront infrastructure that has not consumed the patched cloud component through a subsequent build and deployment.
Business Impact: If exploitation succeeds, the attacker can potentially obtain execution in an internet-facing commerce tier, affecting customer data, storefront integrity, and availability. Even without reliable code execution, memory-corruption attacks against public entry points warrant fast remediation.
Mitigation and Recommendations: SAP states that the third-party patch is already present in the relevant Commerce Cloud release, but customers must create a new build and deploy it to each environment to consume the corrected component. Customers that built and deployed after the specified patch availability date may already be covered; verify deployment history rather than assuming platform patching reached the application automatically. No workaround is available.
3756565 — Credentials Disclosure in SAP BusinessObjects BI Platform Central Management Server — CVSS 7.9, High
What Is Affected: SAP BusinessObjects Business Intelligence Platform Central Management Server, where certain secondary credentials associated with user objects may exist. BusinessObjects is common in enterprise reporting environments and often contains connections to sensitive analytics and data sources.
Nature of the Vulnerability: The application protected certain sensitive credentials using a hard-coded cryptographic key. A highly privileged attacker with local server access could retrieve affected objects and decrypt the stored credentials, turning a local administrative foothold into access to additional authentication material.
Attack Scenarios: Exploitation requires both high privileges and local access, so this is not an internet-facing remote exploit. The realistic scenario is post-compromise credential harvesting by an attacker who has already reached the BusinessObjects server or misuse by an administrator.
Business Impact: Decrypted secondary credentials can expand the blast radius beyond BusinessObjects itself. They may expose data-source accounts, service identities, or other authentication material that attackers can reuse for lateral movement and unauthorized data access.
Mitigation and Recommendations: Implement the SAP patches. For systems that contained secondary credentials before the upgrade, follow SAP KBA 3763536 to create a new manual or automatic key and recode the credentials. Patching without completing the required key-management step may leave the operational response incomplete.
3759854 — Directory Traversal in SAP Manufacturing Integration and Intelligence — CVSS 7.6, High
What Is Affected: SAP MII functionality that saves files through the affected SSCE path. Exploitation requires a privileged attacker, and SAP also notes a user-interaction requirement and conditions outside the attacker’s full control.
Nature of the Vulnerability: Insufficient validation of file paths allows crafted input to write files outside the intended directory. That breaks the expected storage boundary and can affect other components on the MII host.
Attack Scenarios: A privileged attacker can place attacker-influenced content through the affected functionality and rely on a legitimate user to access or process it. The multi-step nature makes exploitation less straightforward than the Critical MII issues, but a successful file write outside the intended path can still become a powerful post-compromise technique.
Business Impact: Unauthorized file placement on an MII host can compromise application integrity, create persistence opportunities, interfere with manufacturing integrations, or affect other applications sharing the server. The business impact is therefore tied to how central MII is to plant operations.
Mitigation and Recommendations: Apply the referenced MII patches. Until then, provide the XMII_Developer role only where required and implement SAP Note 3158613 as recommended by SAP to reduce related injection risk. These steps are compensating controls, not substitutes for the fix.
3758657 — Missing Authorization Check in SAP Manufacturing Integration and Intelligence — CVSS 7.3, High
What Is Affected: SAP MII scheduling-related application functions. The affected functions can be reached remotely and, before the fix, do not enforce the expected authorization validation.
Nature of the Vulnerability: An unauthenticated attacker can access scheduling functionality without proper authorization checks. Depending on the request, the attacker may be able to retrieve, create, modify, or delete scheduling data managed by the application.
Attack Scenarios: No valid account is required. A network-reachable MII instance exposing the affected functions can therefore be probed directly. Although SAP rates the confidentiality, integrity, and availability impact as limited, the lack of authentication makes the issue operationally important.
Business Impact: Manufacturing scheduling data directly influences production coordination. Unauthorized changes may cause planning errors, disrupted interfaces, or operator confusion even when the technical impact is not a full host compromise.
Mitigation and Recommendations: Apply the support packages and patches referenced by SAP. The fix introduces additional role requirements for the affected configuration page. SAP states that no workaround is available, so network restriction and monitoring should only be treated as interim exposure reduction.
3758910 — Missing Authorization Check in SAP Manufacturing Integration and Intelligence Cost Servlet — CVSS 7.3, High
What Is Affected: SAP MII Cost Servlet functionality and its backend operations. Like the scheduling issue above, this is application-level functionality that may be reachable without a valid user session in affected versions.
Nature of the Vulnerability: The Cost Servlet accepts crafted requests with specific parameter values without enforcing the required authorization checks. When processed, those requests can reach backend operations that should be restricted.
Attack Scenarios: No authentication is required. A remote attacker with network access to the affected MII endpoint can attempt to read, create, modify, or delete application-managed business data. The impact is limited compared with the MII code-injection notes, but the attack prerequisite is considerably lower.
Business Impact: Unauthorized manipulation of MII business data can affect reporting, costing, integrations, and operational decision-making. In manufacturing environments, even limited changes can create downstream discrepancies that are difficult to distinguish from normal process data.
Mitigation and Recommendations: Implement the patches referenced in the SAP Security Note. The corrected configuration screen requires additional roles and authorizations. SAP provides no workaround, so prioritize external or broadly reachable MII instances first.
3786038 — Multiple Vulnerabilities in SAP Business AI Platform (Approuter) — CVSS 7.0, High
What Is Affected: SAP Approuter used in SAP BTP and application-routing scenarios. The note bundles multiple CVEs covering information disclosure, certificate validation, authorization, authentication, WebSocket access, request smuggling, denial of service, CSRF, and tenant-context spoofing. Several issues apply only to specific non-default flows such as service2approuter, IAS, back-channel logout, Redis, or subscription-management integrations.
Nature of the Vulnerability: This is not one single flaw. The package contains a set of weaknesses at the routing and trust boundary: insufficient token validation, incomplete certificate checks, weak request authorization, session-integrity gaps, unsafe header forwarding, missing CSRF protection, and denial-of-service conditions. The highest-scored issue can cause sensitive credential material to be sent to an attacker-controlled destination under specific configuration conditions.
Attack Scenarios: Attack prerequisites vary by CVE. Some paths are unauthenticated, while others require low privileges, particular service bindings, or prior observation of session values. The common theme is that Approuter is a security enforcement point; misvalidation at this layer can expose protected backend resources or authentication context.
Business Impact: Approuter often sits in front of BTP applications and backend services. A compromise of routing, session, tenant, or authorization behavior can expose application data, enable limited unauthorized actions, or disrupt availability across multiple services rather than a single business function.
Mitigation and Recommendations: Upgrade @sap/approuter to version 23.0.0 or later. Before implementation, ensure XSUAA redirect URIs are correctly scoped. SAP also documents configuration workarounds for selected CVEs, including binding IAS with x509 credentials and explicitly setting STATE_PARAMETER_SECRET=true. Review the prerequisites in the note to determine which bundled issues actually apply to each deployment.
Medium and Lower Priority Notes (Condensed)
The remaining August items are lower on the CVSS scale, but several are still important because they affect audit integrity, server-side file access, developer-facing UI frameworks, printing services, authorization boundaries, and third-party dependencies. Prioritize them by exposure and business function rather than CVSS alone.
| Note / Advisory | Component / Theme | Severity | Practical Risk |
|---|---|---|---|
| 3770868 | Commerce Cloud / Data Hub — Log4j Core output encoding | Medium 6.5 | Relevant only to non-default XML logging. Crafted input can corrupt structured log output so downstream tooling rejects or drops records, weakening the audit trail. Default configurations are not affected; patch or move away from the vulnerable XML layout. |
| 3757815 | Commerce Cloud — Bouncy Castle timing side channel | Medium 6.5 | Applies to custom code invoking FrodoKEM; standard Commerce configuration does not use the affected functionality. Upgrade the bundled cryptographic library and verify custom cryptography usage. |
| 3753141 | BusinessObjects Web Intelligence — XXE | Medium 6.5 | A low-privileged attacker can upload a crafted spreadsheet whose external references disclose sensitive server-side files when processed as a data source. Patch promptly in BI environments that allow user-supplied spreadsheets. |
| 3758318 | NetWeaver AS Java Adobe Document Services — outdated OpenSSL/libcurl | Medium 6.3 | ADS uses outdated open-source cryptographic and transfer libraries. SAP reports no specific exploit in this context but updates OpenSSL and libcurl to corrected versions. Include Java-side dependencies in the normal patch cycle. |
| 3766473 | SAP Social Intelligence — SQL Injection | Medium 6.3 | A low-privileged authenticated attacker can inject SQL DDL into the underlying database. SAP resolves the issue by removing the vulnerable functionality. |
| 3721424 | NetWeaver AS ABAP Unified Rendering — XSS | Medium 6.3 | An authenticated attacker can create a malicious link that executes content in a victim browser session. Update Unified Rendering to the corrected version and validate SAP GUI for HTML / Web Dynpro dependencies. |
| 3772071 | SAPUI5 — Stored XSS through UI5 Flexibility | Medium 6.1 | A key user with content-adaptation privileges can persist malicious script content in application changes. When another user opens the adapted application, the script executes in the victim session. Update SAPUI5 to the fixed patch levels. |
| GHSA-hc5j-q32w-c25v | pyodata — cross-origin __next handling | Medium 5.9 | pyodata versions before 1.11.2 do not enforce same-origin validation for server-controlled OData pagination URLs. Upgrade to 1.11.2 or later and treat pagination targets as untrusted input. |
| 3745182 | ABAP Platform — OS Command Injection | Medium 5.5 | A high-privileged attacker can reach an internal process-execution path that lacks sufficient security gating. The result can include operating-system writes or system shutdown. Apply the kernel correction; SAP provides no workaround. |
| 3540688 | SAP FICA ODN framework — Code Injection | Medium 5.5, Updated | SAP re-released this previously published note in August. Reassess the latest note revision and current correction guidance even if the item was closed in an earlier patch cycle. |
| 3725940 | SAPSPrint Service — Memory Corruption / DoS | Medium 5.3 | An unauthenticated attacker can send crafted requests that trigger a buffer overflow and temporary service interruption. Apply the SAPSPrint correction; there is no workaround. |
| 3756674 | ABAP Platform — residual memory disclosure | Medium 5.3 | An unauthenticated request to an internal component can expose limited residual data from previously used memory. Apply the kernel patch, including SAP Web Dispatcher archives where applicable. |
| 3778462 | Commerce Cloud Search and Navigation — Netty DoS | Medium 4.8 | Multiple Netty resource-handling issues can make the service unresponsive under crafted HTTP/2 or compressed input. Upgrade the bundled Netty version, then rebuild and redeploy Commerce Cloud. |
| 3770649 | BusinessObjects BI Admin Tools — Missing Authorization | Medium 4.3 | A non-administrative authenticated user can access limited information about administrative functionality. The fix blocks non-admin access to the affected tools. |
| 3669608 | S/4HANA Reprocess Bank Statement Items — Missing Authorization | Medium 4.3 | Authenticated users may use processing rules that were not shared with them. SAP notes that follow-on Notes 3775098 and 3790190 are required for the complete fix, so validate the remediation chain rather than applying one note in isolation. |
| 3781137 | SAP MII — Missing Authorization | Medium 4.3 | A low-privileged user can access restricted account information that may support follow-on attacks against identified users. Patch as part of the broader MII remediation program. |
| 3752864 | CTS Customer Transport Integration Wizard — Missing Authorization | Medium 4.2 | A low-privileged user can modify configuration tables when the relevant ICF service has been explicitly activated. If the Upgrade Integration Wizard is no longer needed, SAP documents deactivation of the SCTS_UPGINT_CHECK_CONFIG service as a temporary mitigation. |
| 3763028 | SAP APO Model Mix Planning — Hard-coded Credentials | Low 3.8 | A high-privileged attacker can abuse a hard-coded credential to bypass an authorization check and delete planning-related restrictions. The fix removes the hard-coded value and introduces a proper authorization check. |
| 3739913 | SAP Data Services Management Console — CSP Misconfiguration | Low 3.7 | An overly permissive Content Security Policy can amplify another browser-side vulnerability. The correction hardens CSP directives; treat this as defense-in-depth for the management console. |
Defender’s Perspective: What This Patch Day Tells Us
Four trends stand out in August.
- Manufacturing application security is now a front-line SAP concern. MII alone accounts for six August notes across Critical, High, and Medium severity. The issues span command execution, XSL processing, path validation, and missing authorization checks, which means patching must be coordinated with manufacturing application owners and plant integration teams.
- Internet-facing commerce and cloud routing remain high-value attack surfaces. Commerce Cloud has both the month’s CVSS 10.0 issue and a separate NGINX memory-corruption item, while Approuter receives a broad security update. These components should be treated as security gateways, not simply application infrastructure.
- Core ABAP protocol and kernel security still matter. The DIAG parsing flaw demonstrates that mature, low-level SAP communication paths can still produce Critical memory-safety risk. Medium kernel issues in the same month reinforce the need for a disciplined SAP kernel patch strategy rather than only implementing application-level notes.
- Patch completion increasingly includes configuration and operational tasks. Secure Transformer and Allowed Hosts must be enabled for MII, Commerce Cloud fixes may require rebuild and redeploy, BusinessObjects may need key rotation, and Approuter exposure depends on runtime configuration. A successful patch process therefore needs a technical validation step after software deployment.
Final Recommendations
Priority 0 — Immediate
- 3771065 — SAP Commerce Cloud Data Hub Adapter: patch and redeploy immediately. If deployment is delayed, restrict /datahubadapter/import/** to known Data Hub egress IP addresses using the SAP-documented IP Filter Set.
- 3765948 — SAP MII code injection: apply the correction immediately and enable Secure Transformer with an explicit Allowed Hosts list. SAP provides no workaround.
- 3714806 — ABAP DIAG memory corruption: move to a corrected kernel patch level as quickly as your regression process allows. There is no workaround.
- 3758900 — SAP MII IllumXSLTServlet code injection: patch and migrate away from the vulnerable servlet; until then, remove the XMII_IllumXSLTServlet action from roles.
- 3727078 — updated NetWeaver AS Java directory traversal: re-open prior change records and confirm the current revision of the note has been implemented.
Priority 1 — High-Severity and Exposed Control Points
- 3772411 — review ADT SQL Console exposure and developer authorizations while applying the fix. Pay particular attention to S_TABU_NAM and S_TABU_DIS assignments.
- 3773203 — confirm Commerce Cloud environments have consumed the NGINX fix through a post-patch build and deployment; platform availability alone does not prove the application has the corrected component.
- 3756565 — patch BusinessObjects and complete any required key rotation and credential recoding for systems with pre-existing secondary credentials.
- 3759854, 3758657, 3758910 — address the High-severity MII cluster together, prioritizing internet-reachable or broadly accessible plant integration systems.
- 3786038 — upgrade SAP Approuter to 23.0.0 or later and validate the configuration-specific prerequisites documented for IAS, service2approuter, WebSocket, Redis, back-channel logout, and subscription-management flows.
Priority 2 — Exposure-Driven Medium and Low Items
- Prioritize BusinessObjects XXE, SAPUI5 stored XSS, Social Intelligence SQL injection, ABAP OS command injection, and SAPSPrint DoS where the affected functionality is reachable by broad user populations or external networks.
- Review custom configurations before deprioritizing third-party-library notes. The Commerce Cloud Log4j and Bouncy Castle issues are not exploitable in default configurations but become relevant when custom XML logging or FrodoKEM code is present.
- Track dependency and follow-on requirements explicitly. The S/4HANA bank statement authorization fix references additional SAP Notes, and several cloud fixes require rebuild/redeploy steps after the corrected version becomes available.
Defense-in-Depth Beyond Patching
- Reduce exposure of MII administration and servlet paths, Commerce Data Hub import endpoints, developer tooling, and SAP management interfaces. Use network allowlists and service deactivation where SAP explicitly documents those controls.
- Harden privileged identities. Review MII developer actions, ADT users, BusinessObjects administrators, and technical service accounts for least privilege, shared credentials, and unnecessary persistent access.
- Increase detection around abnormal DIAG traffic, MII XSL or servlet activity, ADT SQL Console use, Commerce import requests, unexpected BusinessObjects credential activity, and Approuter authentication or forwarding anomalies.
- Validate the correction after implementation. Confirm kernel levels, SAPUI5 versions, Approuter package versions, Commerce build/deploy timestamps, MII system properties, and BusinessObjects key state rather than closing patch tickets based only on package import success.
August’s patch set reinforces a recurring lesson: effective SAP vulnerability management is not a monthly note-import exercise. It requires accurate applicability assessment, platform ownership, configuration validation, exposure reduction, and monitoring across ABAP, Java, cloud, commerce, BI, and manufacturing systems.