SAP Software Update Manager (SUM) – Credential Exposure Through Log Files

August 5, 2026

SAP Software Update Manager (SUM) – Credential Exposure Through Log Files


Impact on Business

A local attacker with low privileges can retrieve sensitive credentials, such as database or SAP administrator passwords, from log files. This has a high impact on the confidentiality of the system and could allow the attacker to escalate privileges within the SAP environment.


Vulnerability Details

Under specific error conditions during an upgrade process, the SAP Software Update Manager (SUM) may write plaintext passwords to its trace and log files. If an error occurs while updating secure properties, the credentials of SAP OS users or database users can be exposed. These log files may be readable by local users, leading to a potential compromise of sensitive authentication data.


Solution

SAP has released SAP Note 3522953 which provides patched versions of the affected components.

The patches can be downloaded from https://me.sap.com/notes/3522953.

Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.


Report Timeline

  • 09/17/2024: Onapsis reports vulnerability to SAP
  • 11/12/2024: SAP issues the patch

References


Advisory Information

  • Public Release Date: 08/05/2026
  • Security Advisory ID: ONAPSIS-2026-0039
  • Researcher(s): Yvan Genuer

Vulnerability Information

  • Vendor: SAP
  • Affected Components: SAP Software Update Manager (SUM) (Check SAP Note 3522953 for detailed information on affected releases)
  • Vulnerability Class: CWE-532: Information Exposure Through Log Files
  • CVSS v3 score: 4.7 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
  • Risk Level: Medium
  • Assigned CVE: CVE-2024-47588
  • Vendor patch Information: SAP Security NOTE 3522953

Affected Components Description

  • SAP Software Update Manager (SUM) 1.1

About our Research Labs

Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.

Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories

This advisory is licensed under a Creative Commons 4.0 BY-ND International License