SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.
08/05/2026
Improper Access Control in SAP Business Explorer (BEx)
Improper Access Control in SAP Business Explorer (BEx) Impact on Business By exploiting this vulnerability, an authenticated malicious user can delete workplace favorites nodes belonging to any other user in the system. This can lead to unauthorized modification of user-specific data and disruption of business workflows within the SAP Business Explorer environment. Vulnerability Details A…
08/05/2026
SAP Bex – Insert Arbitrary URL inside Favorites
SAP Bex – Insert Arbitrary URL inside Favorites Impact on Business An authenticated attacker could exploit this vulnerability to inject arbitrary URLs into the favorites list of any user within the SAP system. This could be leveraged for phishing or social engineering attacks by misleading users into accessing malicious external sites from a trusted interface….
08/05/2026
SAP Bex – Insert Arbitrary Workbook inside Favorites
SAP Bex – Insert Arbitrary Workbook inside Favorites Impact on Business An authenticated attacker could exploit this vulnerability to inject unauthorized content into the favorites workplace of other users. This could be used to mislead users or facilitate further attacks by directing them to malicious workbooks, impacting the integrity of the user’s workspace. Vulnerability Details…
08/05/2026
SAP Bex – Arbitrary Modification of Favorites Nodes Data
SAP Bex – Arbitrary Modification of Favorites Nodes Data Impact on Business An authenticated attacker with low privileges could modify or access data belonging to other users within the SAP Business Explorer (BEx) environment. This could lead to unauthorized data manipulation or access to sensitive workbooks, potentially compromising the integrity and confidentiality of business reports…
08/05/2026
Improper Authorization in SAP BEx (Business Explorer)
Improper Authorization in SAP BEx (Business Explorer) Impact on Business An authenticated attacker with low privileges could gain unauthorized access to sensitive metadata within the SAP system. By exploiting this vulnerability, an attacker can enumerate system usernames, workbook identifiers, and workbook titles. This information disclosure could be used to facilitate further targeted attacks or to…
08/05/2026
SAP Software Update Manager (SUM) – Credential Exposure Through Log Files
SAP Software Update Manager (SUM) – Credential Exposure Through Log Files Impact on Business A local attacker with low privileges can retrieve sensitive credentials, such as database or SAP administrator passwords, from log files. This has a high impact on the confidentiality of the system and could allow the attacker to escalate privileges within the…
08/05/2026
Missing Authorization Check in RFC Enabled Function Module RSWR_DB_DATA_DELETE
Missing Authorization Check in RFC Enabled Function Module RSWR_DB_DATA_DELETE Impact on Business An authenticated attacker could delete data from the RSWR_DATA table, which stores runtime data for user personalization and bookmarks in the Business Explorer (BEx) tool. This could lead to the loss of user-specific configurations, metrics, and a decrease in user productivity within the…
08/05/2026
Missing Authorization Check in SAP NetWeaver
Missing Authorization Check in SAP NetWeaver Impact on Business A remote attacker with low privileges can enumerate all users in the current system client. This information disclosure aids in gathering valid usernames which could be used in subsequent attacks, such as password brute-forcing or social engineering, potentially increasing the attack surface of the system. Vulnerability…
08/05/2026
Missing Authorization and Information Disclosure in SAP Business Warehouse
Missing Authorization and Information Disclosure in SAP Business Warehouse Impact on Business A remote attacker can retrieve detailed configuration information about the SAP system and the underlying operating system. This information disclosure could aid an attacker in planning further attacks by identifying specific versions and configurations of the target environment. Vulnerability Details The remote-enabled function…
