🔥 この記事の詳細
2026-09-11 更新
B
今週中

SAP KernelおよびNetWeaver Message Serverにおいて、認証なしでリモートからコード実行が可能な2つの深刻な脆弱性

脆弱性🌐 英語ソース📰 3記事🌐 3 countries
🇪🇺 EU · 🇯🇵 Japan · 🇹🇭 Thailand
🖥️ 製品SAP
🔢 CVECVE-2026-44756CVE-2026-58240
📅 2026-09-11📰 cert_eu
📌 一言でいうと
SAP KernelおよびNetWeaver Message Serverにおいて、認証なしでリモートからコード実行が可能な2つの深刻な脆弱性が公開されました。特にCVE-2026-44756(OVERPASS)はCVSS 10.0の最高評価であり、メモリ破損を通じてOSコマンドの実行が可能です。もう一方のCVE-2026-58240(S4GET)は認証チェックの不備によるものです。攻撃者が成功した場合、システム全体の完全な制御を奪われるリスクがあります。
🔍該当判定
  • 社内でSAP製品(ERP等)を導入・利用している
  • SAP Kernel または SAP NetWeaver Message Server を運用している
  • SAP Extended Passport (EPP) を利用して認証を行っている
上記いずれにも該当しない → 静観でOK
該当時の対応
速やかにSAP Security Notes 3747649 および 3759472 を適用し、パッチを更新してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】SAP Kernel および NetWeaver Message Server 脆弱性対応について

お疲れさまです。SAP製品の深刻な脆弱性に関する情報共有です。

■ 概要
SAP KernelおよびNetWeaver Message Serverにおいて、認証なしでリモートからOSコマンドを実行可能な脆弱性が2件発見されました。特にCVE-2026-44756はCVSS 10.0と極めて危険な状態です。

■ 影響範囲
- SAP Kernel (SAP Extended Passport処理部分)
- SAP NetWeaver Message Server

■ 対応手順
1. SAP Security Notes 3747649 および 3759472 の内容を確認してください。
2. 該当する製品に最新のセキュリティパッチを適用してください。

■ 参考情報
- CERT-EU アドバイザリ
- SAP Security Notes

対応優先度: 高
対応期限: 至急
Subject: [Urgent] Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

Dear IT/Security Team,

This is an alert regarding two critical vulnerabilities in SAP products that allow unauthenticated remote code execution (RCE).

■ Overview
- CVE-2026-44756 (OVERPASS): Memory corruption in SAP Extended Passport processing (CVSS 10.0).
- CVE-2026-58240 (S4GET): Missing authentication check in SAP NetWeaver Message Server (CVSS 9.8).

■ Affected Scope
- SAP Kernel
- SAP NetWeaver Message Server

■ Remediation Steps
1. Review SAP Security Notes 3747649 and 3759472.
2. Apply the recommended security patches immediately to prevent full system compromise.

■ Reference
- CERT-EU Advisory
- SAP Security Notes

Priority: High
Deadline: Immediate