SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.
08/05/2026
Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf
Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf Impact on Business An unauthenticated attacker can inject malicious code into the SAP Adobe Document Services (ADS) component. This can lead to the disclosure of sensitive system information and cause a denial of service (DoS) condition, rendering the PDF generation service unavailable and disrupting…
07/30/2026
Arbitrary File Read in SAP SRM
Arbitrary File Read in SAP SRM Impact on Business An unauthenticated remote attacker can exploit this vulnerability to read arbitrary files from the operating system of the affected SAP server. This can lead to the disclosure of highly sensitive information, including system credentials and configuration files, which could be leveraged to further compromise the system…
07/30/2026
SAP SRM – Blind XXE in /srm/messaging
SAP SRM – Blind XXE in /srm/messaging Impact on Business A remote, unauthenticated attacker can exploit this vulnerability to read arbitrary files from the file system of the application server. This has a high impact on the confidentiality of the system, potentially exposing sensitive business data, credentials, and system configurations. Additionally, it allows the attacker…
07/30/2026
Memory Corruption in SAP NetWeaver Master Data Management
Memory Corruption in SAP NetWeaver Master Data Management Impact on Business A remote unauthenticated attacker can cause a Denial of Service (DoS) condition in the SAP NetWeaver Master Data Management server. By exploiting this vulnerability, the attacker can terminate the service, rendering it unavailable for legitimate users and disrupting business processes. Vulnerability Details A memory…
07/30/2026
Memory Corruption in SAP NetWeaver Master Data Management
Memory Corruption in SAP NetWeaver Master Data Management Impact on Business An unauthenticated remote attacker can cause the SAP MDM Server to crash by sending a specially crafted packet. This results in a Denial of Service (DoS), rendering the system unavailable to legitimate users and disrupting business processes that rely on Master Data Management services….
07/30/2026
Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler
Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler Impact on Business A remote, authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability to trigger memory corruption or an information leak. This can lead to the crashing of work processes, causing a high impact on system availability, and…
09/15/2025
Open Redirect in SAP HANA XSA UAA Server
Open Redirect in SAP HANA XSA UAA Server Impact on Business The open redirect vulnerability allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks. The phishers may then steal victim’s credentials or other important data that can be used in other exploitation chains. This has limited impact on the confidentiality, integrity and availability of the…
08/28/2025
Arbitrary execution of RFC functions through SHDB_TOOLS_RFC_WRAPPER
Arbitrary execution of RFC functions through SHDB_TOOLS_RFC_WRAPPER Impact on Business By exploiting this vulnerability a remote attacker could trick users into accessing specially crafted URL(s) that could trigger certain actions on the SAP System by triggering specific events. Vulnerability Details Due to the unrestricted scope of the RFC function module(SHDB_TOOLS_RFC_WRAPPER), SAP BASIS – versions 731,…
08/28/2025
Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_GET_OBJECTS
Arbitrary execution of RFC functions through SDF-CCM_AGS_CC_GET_OBJECTS Impact on Business This vulnerability allows an attacker to execute any function that exists in the system, therefore if there is, for example, a function that can delete/overwrite files or execute operating system commands, this could be affected from the business to a denial of service. Vulnerability Details…
