SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.

09/27/2024

Reflected Cross Site Scripting in CRM_BSP_FRAME class

Reflected Cross Site Scripting in CRM_BSP_FRAME class Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description SAP_ABA 700 SP 07-40 SAP_ABA 701…

09/20/2024

Reflected Cross Site Scripting in CL_HTTP_EXT_SERVICE_POST_DEMO class

Reflected Cross Site Scripting in CL_HTTP_EXT_SERVICE_POST_DEMO class Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description SAP_ABA 700 SP 07-40 SAP_ABA 701…

09/20/2024

Reflected Cross Site Scripting in PING_PONG demo app

Reflected Cross Site Scripting in PING_PONG demo app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description SAP_BASIS 740 SP 09-28 SAP_BASIS…

09/19/2024

Reflected Cross Site Scripting in COVER_BY_BSP app

Reflected Cross Site Scripting in COVER_BY_BSP app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description This vulnerability affects ST 720 SP…

09/18/2024

Reflected Cross Site Scripting in SESSION_HTML app

Reflected Cross Site Scripting in SESSION_HTML app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description This vulnerability affects ST 720 SP…

09/18/2024

Multiple Reflected Cross Site Scripting vulnerabilities in SBSPEXT_PHTMLB package

Multiple Reflected Cross Site Scripting vulnerabilities in SBSPEXT_PHTMLB package Impact On Business By exploiting any of these vulnerabilities a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal user sessions or other information. Affected Components Description SAP_BASIS 700 SP…

09/18/2024

Reflected Cross Site Scripting in WBA_SESS_REPORT app

Reflected Cross Site Scripting in WBA_SESS_REPORT app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description This vulnerability affects ST 720 SP…

09/18/2024

Arbitrary Redirect in Biller Direct 7.50

Arbitrary Redirect in Biller Direct 7.50 Impact On Business The users of SAP BillerDirect could be targeted and redirected to a malicious site, potentially stealing their credentials or compromising their accounts through the combination of other techniques. Affected Components Description Tested on following versions: SAP Biller Direct 7.0 (FSCM-BD) Vulnerability Details SAP Biller Direct allows…

03/07/2024

Unauthenticated Information Disclosure in ObjectAnalyzer P4 service

Unauthenticated Information Disclosure in ObjectAnalyzer P4 service Impact On Business An unauthenticated attacker with access to the P4 port of a java-based SAP solution, would be able to exfiltrate sensitive technical information that could be leveraged for future attacks. This vulnerability is part of a bigger family named P4CHAINS. This group of bugs may cause…

Page 7 of 13