Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler
July 30, 2026
Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler
Impact on Business
A remote, authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability to trigger memory corruption or an information leak. This can lead to the crashing of work processes, causing a high impact on system availability, and allows the reading of out-of-bounds memory, resulting in a high impact on the confidentiality of the system and its business applications.
Vulnerability Details
In SAP NetWeaver Application Server ABAP and ABAP Platform, a Server-Side Request Forgery (SSRF) vulnerability in the HTTP handler of the BIC Document application exists. An authenticated attacker can manipulate destination identifiers in remote calls, forcing the vulnerable server to connect to an attacker-controlled system.
By providing malformed length and data parameters during the processing of the response, the attacker can trigger an out-of-bounds read or memory corruption. This can result in the exposure of sensitive information temporarily stored in memory or cause the application server’s work processes to crash.
Solution
SAP has released SAP Note 3611184 which provides patched versions of the affected components.
The patches can be downloaded from https://me.sap.com/notes/3611184.
Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.
Report Timeline
- 05/15/2025: Onapsis reports vulnerability to SAP
- 08/12/2025: SAP issues the patch
References
Advisory Information
- Public Release Date: 07/30/2026
- Security Advisory ID: ONAPSIS-2026-0016
- Researcher(s): Fabian Hagg
Vulnerability Information
- Vendor: SAP
- Affected Components: SAP NetWeaver ABAP, S4COREOP, Strategic Enterprise Management (SEM-BW) (Check SAP Note 3611184 for detailed information on affected releases)
- Vulnerability Class: Server-Side Request Forgery (SSRF) and Out-of-bounds Read
- CVSS v3 score: 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
- Risk Level: High
- Assigned CVE: CVE-2025-42976
- Vendor patch Information: SAP Security NOTE 3611184
Affected Components Description
- S4COREOP 104 – 108
- Strategic Enterprise Management (SEM-BW) (Release 736, 747, 748)

About our Research Labs
Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.
Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories
This advisory is licensed under a Creative Commons 4.0 BY-ND International License
