SAP® and Oracle® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP, Oracle, and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.

08/28/2025

Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_GET_OBJECTS

Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_GET_OBJECTS Impact on Business This vulnerability allows an attacker to execute any function that exists in the system, therefore if there is, for example, a function that can delete/overwrite files or execute operating system commands, this could be affected from the business to a denial of service. Vulnerability Details…

08/26/2025

Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_SIM_API_LOAD

Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_SIM_API_LOAD Impact on Business This vulnerability allows an attacker to execute any function that exists in the system, therefore if there is, for example, a function that can delete/overwrite files or execute operating system commands, this could be affected from the business to a denial of service. Vulnerability Details…

09/27/2024

Arbitrary execution of RFC functions through CCM_AGS_CC_SIM_API_START

Arbitrary execution of RFC functions through CCM_AGS_CC_SIM_API_START Impact On Business This vulnerability allows an attacker to execute any function that exists in the system, therefore if there is, for example, a function that can delete/overwrite files or execute operating system commands, this could be affected from the business to a denial of service. Affected Components…

09/27/2024

Reflected Cross Site Scripting in CRM_BSP_FRAME class

Reflected Cross Site Scripting in CRM_BSP_FRAME class Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description SAP_ABA 700 SP 07-40 SAP_ABA 701…

09/20/2024

Reflected Cross Site Scripting in CL_HTTP_EXT_SERVICE_POST_DEMO class

Reflected Cross Site Scripting in CL_HTTP_EXT_SERVICE_POST_DEMO class Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description SAP_ABA 700 SP 07-40 SAP_ABA 701…

09/20/2024

Reflected Cross Site Scripting in PING_PONG demo app

Reflected Cross Site Scripting in PING_PONG demo app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description SAP_BASIS 740 SP 09-28 SAP_BASIS…

09/19/2024

Reflected Cross Site Scripting in COVER_BY_BSP app

Reflected Cross Site Scripting in COVER_BY_BSP app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description This vulnerability affects ST 720 SP…

09/18/2024

Reflected Cross Site Scripting in SESSION_HTML app

Reflected Cross Site Scripting in SESSION_HTML app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description This vulnerability affects ST 720 SP…

09/18/2024

Reflected Cross Site Scripting in WBA_SESS_REPORT app

Reflected Cross Site Scripting in WBA_SESS_REPORT app Impact On Business By exploiting this vulnerability a remote attacker could trick users into clicking malicious links and depending on the level of protection that the browser provides, the attacker could potentially steal their user sessions or other information. Affected Components Description This vulnerability affects ST 720 SP…

Page 1 of 2