CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-27636

unknowncovered by 2 sourcesfirst seen 2026-07-14
SAP has fixed vulnerabilities in SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, SAP NetWeaver Application Server Java, SAProuter, SAP Change and Transport System Attach Tool, SAP NetWeaver Enterprise Portal, SAP S/4HANA modules, SAP Fiori Launchpad, SAP CRM WebClient UI, SAP HANA Database user self service tools, and SAP Commerce Cloud. Update: Due to a processing error, no references were provided. This has been corrected. There are no further substantive changes. The vulnerabilities involve various security issues such as: - memory corruption in SAP NetWeaver Application Server ABAP - HTTP Request Smuggling in SAP Approuter - insecure OAuth2 sample credentials in SAP Commerce Cloud - directory traversal in SAP NetWeaver Application Server Java - DLL hijacking in SAProuter on Windows. - Additionally, there are Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver Application Server Java and Enterprise Portal and missing authorization controls in SAP S/4HANA modules. - SAP Change and Transport System Attach Tool is vulnerable to remote code execution due to insecure deserialization. - SAP HANA user self service tools allow information transfer without authentication. The vulnerabilities can lead to unauthorized access, data manipulation, information leaks, and disruption of availability. Some vulnerabilities require authentication, while others can be exploited by unauthorized users. Various vulnerabilities are specific to components used within SAP environments, such as Apache Camel within the SAP Integration Suite and Apache Tomcat within SAP Commerce Cloud.

CSIRTS triage

What
SAP has fixed various vulnerabilities including memory corruption and HTTP request smuggling.
Who is affected
Users of various SAP products are affected.
Urgency
Remediation is important as vulnerabilities could lead to significant security issues.
Action
Update all affected SAP products to the latest versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-27636

Get an email if CVE-2025-27636 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2025-27636

CVE.org record

Embed the live status

CVE-2025-27636 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-27636 status](https://www.csirts.com/badge/CVE-2025-27636)](https://www.csirts.com/cve/CVE-2025-27636)