For its March 2026 Security Patch Day, SAP released 15 security notes, headlined by two critical-severity fixes for SAP Quotation Management Insurance (FS-QUO) and SAP NetWeaver Enterprise Portal Administration.
Key Details and Impact
- SAP FS-QUO: This vulnerability stems from an outdated Apache Log4j 1.2.17 artifact. An unprivileged attacker can exploit a deserialization flaw in the
SocketServer class to execute malicious code remotely.
- SAP NetWeaver: This flaw affects Enterprise Portal Administration due to insufficient validation during content deserialization. While it requires high privileges for successful exploitation, it could lead to full system compromise or service disruption.
- Other Fixes: The March release also includes one high-severity note and 12 medium-to-low severity notes covering products like SAP Supply Chain Management and SAP BusinessObjects.
Recommended Actions
- Prioritize FS-QUO: Immediately apply SAP Security Note #3698553 if you run Quotation Management Insurance.
- Restrict Portal Admin: Patch Note #3714585 and ensure administrative interfaces are limited to trusted internal users.
- Audit Third-Party Libraries: Review your environment for other “sidecar” services that may still use vulnerable legacy libraries.