SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.
07/30/2026
Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST
Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST Impact on Business A remote authenticated attacker can discover detailed information about installed software components and their versions on the application server. This information disclosure aids in fingerprinting the system, potentially facilitating further attacks by identifying specific vulnerable components. This has a low impact…
07/30/2026
Missing Authorization Check in SAP ST-PI
Missing Authorization Check in SAP ST-PI Impact on Business A remote attacker can obtain sensitive information such as installed components, versions, patches, and user IDs from the application server. This information can be used to fingerprint the system and plan further attacks, impacting the confidentiality of the system. Vulnerability Details The remote-enabled function module /SDF/SWCM_GET_SYSTEM_INFO…
07/30/2026
Missing Authorization Check in RFC Enabled Function /BDL/_READ_LOG
Missing Authorization Check in RFC Enabled Function /BDL/_READ_LOG Impact on Business A remote authenticated attacker can read log messages and specific fields, such as usernames, from the application server. This has a low impact on the confidentiality of the system and its business applications. Vulnerability Details The remote-enabled function module /BDL/_READ_LOG allows authenticated users to…
07/30/2026
Missing Authorization Check and Information Disclosure in RFC enabled function AGS_SMT_TSAT_READ_SW_INFO
Missing Authorization Check and Information Disclosure in RFC enabled function AGS_SMT_TSAT_READ_SW_INFO Impact on Business A remote attacker can retrieve a list of installed software components and their versions from the affected system. This information disclosure could aid an attacker in identifying specific component versions to target in further attacks, potentially increasing the risk of successful…
07/30/2026
SAP SRM – XSS in SRM Live Auction
SAP SRM – XSS in SRM Live Auction Impact on Business A successful Cross-Site Scripting (XSS) attack could allow an unauthenticated attacker to hijack user sessions or force victims to perform unintended actions within the SAP SRM system. This can lead to unauthorized access and potential manipulation of business data, impacting the confidentiality and integrity…
07/30/2026
SAP SRM – Open Redirect in SRM Live Auction
SAP SRM – Open Redirect in SRM Live Auction Impact on Business An open redirect vulnerability in SAP Supplier Relationship Management allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. A successful attack can lead to various types of exploitation depending on the victim’s privileges, potentially impacting the integrity and…
07/30/2026
SAP SRM – Information Disclosure in SRM Live Auction
SAP SRM – Information Disclosure in SRM Live Auction Impact on Business An unauthenticated attacker can access sensitive system information over the network. This information disclosure could provide an attacker with details about the system’s configuration, versions, and environment, which could be used to plan further attacks. This has a low impact on the confidentiality…
07/30/2026
SAP SRM – XSS in tc | ~mdm | ~srmcat | ~uisearch
SAP SRM – XSS in tc\~mdm\~srmcat\~uisearch Impact on Business A successful Cross-Site Scripting (XSS) attack could allow an unauthenticated attacker to execute malicious scripts in the context of the victim’s browser. Depending on the victim’s privileges, this could lead to session hijacking or unauthorized actions performed on behalf of the user within the SAP SRM…
07/30/2026
SAP Netweaver JAVA – Information Disclosure in DispatchServlet
SAP Netweaver JAVA – Information Disclosure in DispatchServlet Impact on Business An unauthenticated attacker can retrieve a list of valid usernames from the affected SAP system. This information disclosure aids attackers in identifying valid accounts, which can be leveraged to facilitate further attacks such as brute-force attempts or social engineering campaigns, potentially compromising the system’s…
