Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Addresses Critical Bugs in FS-QUO and NetWeaver

SAP Addresses Critical Bugs in FS-QUO and NetWeaver

Posted on March 10, 2026 By CWS

On Tuesday, SAP, a leading enterprise security company, released 15 new security notes as part of its March 2026 Security Patch Day initiative. These updates aim to address critical security vulnerabilities in their systems.

Critical Vulnerabilities in FS-QUO and NetWeaver

The most significant of these updates concern critical flaws identified in Quotation Management Insurance (FS-QUO) and NetWeaver Enterprise Portal Administration. SAP has highlighted a severe code injection vulnerability within FS-QUO, which is recorded as CVE-2019-17571 with a CVSS score of 9.8.

This vulnerability, initially discovered in December 2019, involves the deserialization of untrusted data in Apache Log4j, potentially allowing remote code execution under specific circumstances.

Another critical vulnerability, known as CVE-2026-27685, also involves deserialization of untrusted data. With a CVSS score of 9.1, this issue could enable attackers to introduce malicious data that, when processed, might lead to code execution or even a denial-of-service (DoS).

Additional Security Concerns Addressed

In addition to these critical vulnerabilities, SAP’s March 2026 patch includes a fix for CVE-2026-27689, a high-severity DoS vulnerability in their Supply Chain Management system. This flaw allows for the repeated execution of a function with a large loop control parameter, which can exhaust system resources.

The remaining security notes address medium-severity issues across various SAP products such as NetWeaver, Business One, Business Warehouse, S/4HANA, and others. These issues include server-side request forgery (SSRF), missing authorization checks, SQL injections, cross-site scripting (XSS), insecure storage, DLL hijacking, and DoS vulnerabilities.

Importance of Timely Updates

SAP has not reported any active exploitation of these vulnerabilities in the wild. However, users are strongly advised to update their systems promptly to mitigate potential risks.

Keeping systems updated is crucial to maintain security and prevent attackers from exploiting these vulnerabilities. Regular patching ensures that potential entry points for cyber threats are minimized, safeguarding sensitive enterprise data.

By addressing these vulnerabilities, SAP continues to reinforce its commitment to providing secure and reliable software solutions for its users worldwide.

Security Week News Tags:code injection, Cybersecurity, Deserialization, FS-QUO, NetWeaver, Patch, SAP, Security, software update, Vulnerabilities

Post navigation

Previous Post: KadNap Malware Uses Asus Routers for Stealth Botnet
Next Post: Chinese Cyber Threat Targets Qatar Amid Middle East Unrest

Related Posts

Doppel Raises  Million at 0 Million Valuation Doppel Raises $70 Million at $600 Million Valuation Security Week News
AI Security Firm Polygraf Raises .5 Million in Seed Funding AI Security Firm Polygraf Raises $9.5 Million in Seed Funding Security Week News
Critical Flowise Vulnerability Exploit Code Released Critical Flowise Vulnerability Exploit Code Released Security Week News
Samsung Patches Zero-Day Exploited Against Android Users Samsung Patches Zero-Day Exploited Against Android Users Security Week News
CISA Alerts on Active Gitea Vulnerability Exploitation CISA Alerts on Active Gitea Vulnerability Exploitation Security Week News
DraftKings Hacker Sentenced to 18 Months in Prison DraftKings Hacker Sentenced to 18 Months in Prison Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark