SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.

08/05/2026

Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf

Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf Impact on Business An unauthenticated attacker can inject malicious code into the SAP Adobe Document Services (ADS) component. This can lead to the disclosure of sensitive system information and cause a denial of service (DoS) condition, rendering the PDF generation service unavailable and disrupting…

07/30/2026

Arbitrary File Read in SAP SRM

Arbitrary File Read in SAP SRM Impact on Business An unauthenticated remote attacker can exploit this vulnerability to read arbitrary files from the operating system of the affected SAP server. This can lead to the disclosure of highly sensitive information, including system credentials and configuration files, which could be leveraged to further compromise the system…

07/30/2026

SAP SRM – Blind XXE in /srm/messaging

SAP SRM – Blind XXE in /srm/messaging Impact on Business A remote, unauthenticated attacker can exploit this vulnerability to read arbitrary files from the file system of the application server. This has a high impact on the confidentiality of the system, potentially exposing sensitive business data, credentials, and system configurations. Additionally, it allows the attacker…

07/30/2026

Memory Corruption in SAP NetWeaver Master Data Management

Memory Corruption in SAP NetWeaver Master Data Management Impact on Business A remote unauthenticated attacker can cause a Denial of Service (DoS) condition in the SAP NetWeaver Master Data Management server. By exploiting this vulnerability, the attacker can terminate the service, rendering it unavailable for legitimate users and disrupting business processes. Vulnerability Details A memory…

07/30/2026

Memory Corruption in SAP NetWeaver Master Data Management

Memory Corruption in SAP NetWeaver Master Data Management Impact on Business An unauthenticated remote attacker can cause the SAP MDM Server to crash by sending a specially crafted packet. This results in a Denial of Service (DoS), rendering the system unavailable to legitimate users and disrupting business processes that rely on Master Data Management services….

07/30/2026

Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler

Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler Impact on Business A remote, authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability to trigger memory corruption or an information leak. This can lead to the crashing of work processes, causing a high impact on system availability, and…

09/15/2025

Open Redirect in SAP HANA XSA UAA Server

Open Redirect in SAP HANA XSA UAA Server Impact on Business The open redirect vulnerability allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks. The phishers may then steal victim’s credentials or other important data that can be used in other exploitation chains. This has limited impact on the confidentiality, integrity and availability of the…

08/28/2025

Arbitrary execution of RFC functions through SHDB_TOOLS_RFC_WRAPPER

Arbitrary execution of RFC functions through SHDB_TOOLS_RFC_WRAPPER Impact on Business By exploiting this vulnerability a remote attacker could trick users into accessing specially crafted URL(s) that could trigger certain actions on the SAP System by triggering specific events. Vulnerability Details Due to the unrestricted scope of the RFC function module(SHDB_TOOLS_RFC_WRAPPER), SAP BASIS – versions 731,…

08/28/2025

Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_GET_OBJECTS

Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_GET_OBJECTS Impact on Business This vulnerability allows an attacker to execute any function that exists in the system, therefore if there is, for example, a function that can delete/overwrite files or execute operating system commands, this could be affected from the business to a denial of service. Vulnerability Details…

Page 1 of 7