B
今週中
SAP KernelおよびNetWeaver Message Serverにおいて、認証なしでリモートからコード実行が可能な2つの深刻な脆弱性
📌 一言でいうと
SAP KernelおよびNetWeaver Message Serverにおいて、認証なしでリモートからコード実行が可能な2つの深刻な脆弱性が公開されました。特にCVE-2026-44756(OVERPASS)はCVSS 10.0の最高評価であり、メモリ破損を通じてOSコマンドの実行が可能です。もう一方のCVE-2026-58240(S4GET)は認証チェックの不備によるものです。攻撃者が成功した場合、システム全体の完全な制御を奪われるリスクがあります。
🔍該当判定
- 社内でSAP製品(ERP等)を導入・利用している
- SAP Kernel または SAP NetWeaver Message Server を運用している
- SAP Extended Passport (EPP) を利用して認証を行っている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
速やかにSAP Security Notes 3747649 および 3759472 を適用し、パッチを更新してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】SAP Kernel および NetWeaver Message Server 脆弱性対応について
お疲れさまです。SAP製品の深刻な脆弱性に関する情報共有です。
■ 概要
SAP KernelおよびNetWeaver Message Serverにおいて、認証なしでリモートからOSコマンドを実行可能な脆弱性が2件発見されました。特にCVE-2026-44756はCVSS 10.0と極めて危険な状態です。
■ 影響範囲
- SAP Kernel (SAP Extended Passport処理部分)
- SAP NetWeaver Message Server
■ 対応手順
1. SAP Security Notes 3747649 および 3759472 の内容を確認してください。
2. 該当する製品に最新のセキュリティパッチを適用してください。
■ 参考情報
- CERT-EU アドバイザリ
- SAP Security Notes
対応優先度: 高
対応期限: 至急
お疲れさまです。SAP製品の深刻な脆弱性に関する情報共有です。
■ 概要
SAP KernelおよびNetWeaver Message Serverにおいて、認証なしでリモートからOSコマンドを実行可能な脆弱性が2件発見されました。特にCVE-2026-44756はCVSS 10.0と極めて危険な状態です。
■ 影響範囲
- SAP Kernel (SAP Extended Passport処理部分)
- SAP NetWeaver Message Server
■ 対応手順
1. SAP Security Notes 3747649 および 3759472 の内容を確認してください。
2. 該当する製品に最新のセキュリティパッチを適用してください。
■ 参考情報
- CERT-EU アドバイザリ
- SAP Security Notes
対応優先度: 高
対応期限: 至急
Subject: [Urgent] Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
Dear IT/Security Team,
This is an alert regarding two critical vulnerabilities in SAP products that allow unauthenticated remote code execution (RCE).
■ Overview
- CVE-2026-44756 (OVERPASS): Memory corruption in SAP Extended Passport processing (CVSS 10.0).
- CVE-2026-58240 (S4GET): Missing authentication check in SAP NetWeaver Message Server (CVSS 9.8).
■ Affected Scope
- SAP Kernel
- SAP NetWeaver Message Server
■ Remediation Steps
1. Review SAP Security Notes 3747649 and 3759472.
2. Apply the recommended security patches immediately to prevent full system compromise.
■ Reference
- CERT-EU Advisory
- SAP Security Notes
Priority: High
Deadline: Immediate
Dear IT/Security Team,
This is an alert regarding two critical vulnerabilities in SAP products that allow unauthenticated remote code execution (RCE).
■ Overview
- CVE-2026-44756 (OVERPASS): Memory corruption in SAP Extended Passport processing (CVSS 10.0).
- CVE-2026-58240 (S4GET): Missing authentication check in SAP NetWeaver Message Server (CVSS 9.8).
■ Affected Scope
- SAP Kernel
- SAP NetWeaver Message Server
■ Remediation Steps
1. Review SAP Security Notes 3747649 and 3759472.
2. Apply the recommended security patches immediately to prevent full system compromise.
■ Reference
- CERT-EU Advisory
- SAP Security Notes
Priority: High
Deadline: Immediate