SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.
09/17/2026
SAP Netweaver JAVA Enterprise Portal – Translation Worklist Authentication Insecure Deserialization
SAP Netweaver JAVA Enterprise Portal – Translation Worklist Authentication Insecure Deserialization Impact on Business A remote, authenticated attacker can exploit an insecure deserialization vulnerability to execute arbitrary operating system commands on the target system. This has a critical impact on the confidentiality, integrity, and availability of the system and its business applications, potentially allowing full…
09/17/2026
SAP ADS – Overwrite arbitrary file by PDF leading to RCE
SAP ADS – Overwrite arbitrary file by PDF leading to RCE Impact on Business An authenticated attacker with high privileges can exploit this vulnerability to overwrite arbitrary files on the host operating system. This can ultimately lead to remote command execution, allowing the attacker to fully compromise the confidentiality, integrity, and availability of the affected…
07/30/2026
Unauthenticated Java Deserialization in SAP SRM
Unauthenticated Java Deserialization in SAP SRM Impact on Business A remote, unauthenticated attacker can exploit a Java deserialization vulnerability in SAP Supplier Relationship Management (SRM). Successful exploitation could allow the attacker to execute arbitrary commands on the operating system with the privileges of the SAP Administrator (sidadm). This has a critical impact on the confidentiality,…
07/30/2026
Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network
Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network Impact on Business A remote, authenticated attacker with high privileges can exploit a Java deserialization vulnerability to execute arbitrary operating system commands. This can lead to a full compromise of the affected system, severely impacting the confidentiality, integrity, and availability of the…
07/30/2026
SAP NetWeaver AS Java ILM Data Archiving Service Insecure Deserialization
SAP NetWeaver AS Java ILM Data Archiving Service Insecure Deserialization Impact on Business An authenticated attacker with high privileges can exploit this vulnerability to execute arbitrary operating system commands on the server. This could lead to a full compromise of the affected system, significantly impacting the confidentiality, integrity, and availability of the business application and…
07/30/2026
SAP Netweaver JAVA – Log Viewer – Insecure JAVA Deserialization
SAP Netweaver JAVA – Log Viewer – Insecure JAVA Deserialization Impact on Business Successful exploitation of this vulnerability can fully compromise the SAP system. An authenticated attacker with high privileges could execute arbitrary OS commands, leading to a complete compromise of confidentiality, integrity, and availability of the affected system and its business applications. Vulnerability Details…
07/30/2026
ABAP Command Injection in CNVCF_JSTAT_UP RFC function call (S4CORE)
ABAP Command Injection in CNVCF_JSTAT_UP RFC function call (S4CORE) Impact on Business Successful exploitation of this vulnerability enables authenticated attackers to run arbitrary OS commands, resulting in full system compromise. This has a critical impact on the confidentiality, integrity, and availability of the system and its business applications. Vulnerability Details A remote-enabled function module named…
08/18/2025
IS-OIL – OS Command Injection FM OIB_QCI_SERVER
IS-OIL – OS Command Injection FM OIB_QCI_SERVER Impact On Business Successful attack could allow an attacker to execute blind operating system command as SAP System Administrator user (sidadm). Lead to full compromise the SAP Netweaver System. Vulnerability Details An OS command injection vulnerability exists in FM OIB_QCI_SERVER, delivered by OIB_QCI package and provided by IS-OIL…
07/23/2025
SAPStartSrv – Pre-auth buffer overflow
SAPStartSrv – Pre-auth buffer overflow Impact On Business If parameter service/localconnection = compat : Remotely, an unauthenticated attacker could use it to execute arbitrary commands on the OS side as NT System or root users. If parameter service/localconnection is not set : Locally, an authenticated attacker with low privileges could use it to execute arbitrary…
