By exploiting this vulnerability an attacker could shut down all SAP systems.
Please fill out the form to download the security advisory.
Further Reading
Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf
Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf Impact on Business An unauthenticated attacker can inject malicious code into the SAP Adobe Document Services (ADS) component. This can lead to the disclosure of sensitive system information and cause a denial of service (DoS) condition, rendering the PDF generation service unavailable and disrupting…
Information Exposure in SAP Bex Workbooks
Information Exposure in SAP Bex Workbooks Impact on Business An authenticated attacker can gain unauthorized access to metadata regarding workbooks within the SAP BW system. This exposure of information allows for the enumeration of workbook names and IDs, which could be used to facilitate further targeted actions or information gathering. Vulnerability Details The RFC-enabled function…
Information Disclosure in SAP Business Explorer (BEx)
Information Disclosure in SAP Business Explorer (BEx) Impact on Business By exploiting this vulnerability, an authenticated attacker can gain unauthorized access to sensitive workplace information belonging to other users. This includes details such as favorite shortcuts, internal URLs, and workbook identifiers. Such information disclosure can be used to map internal business processes or facilitate more…
