SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.
07/30/2026
Missing Authorization Check in SSC_E2E_STORE_BDCDATA
Missing Authorization Check in SSC_E2E_STORE_BDCDATA Impact on Business A remote, authenticated attacker can exploit a missing authorization check to insert arbitrary records into the INDX database table. This vulnerability has a low impact on the integrity of the system and its business applications. Vulnerability Details The remote-enabled function module SSC_E2E_STORE_BDCDATA within the SAP S4 Foundation…
07/30/2026
Open Redirection in SAP NetWeaver Application Server ABAP
Open Redirection in SAP NetWeaver Application Server ABAP Impact on Business An unauthenticated remote attacker can redirect users to arbitrary untrusted sites using a malicious link. Since the link initially points to a trusted server, phishing attempts are more likely to succeed, potentially leading to credential theft or other malicious actions against the victim. Vulnerability…
07/30/2026
SAP MDM Server – MDM Console Session Hijacking
SAP MDM Server – MDM Console Session Hijacking Impact on Business An unauthenticated remote attacker can hijack active sessions on the SAP MDM Console. This allows the attacker to access sensitive information, such as application logs and system details, and perform administrative actions, including the deletion of repositories. This vulnerability impacts the confidentiality, integrity, and…
07/30/2026
Reflected Cross-Site Scripting (XSS) in SAP NetWeaver
Reflected Cross-Site Scripting (XSS) in SAP NetWeaver Impact on Business Successful exploitation of this vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript code into the application. This code is executed within the victim’s browser session when they interact with a crafted URL. This can lead to session hijacking, redirection to malicious websites, defacement…
07/30/2026
Reflected Cross-Site Scripting (XSS) through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler
Reflected Cross-Site Scripting (XSS) through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler Impact on Business Successful exploitation of the identified vulnerability enables an attacker to run malicious scripts in the browser of end users. This could cause website defacement, phishing attacks, or unintended requests being delivered to the vulnerable application server on behalf…
04/13/2026
SAP BEx -Denial of Service and Arbitrary Favorites Modification/Deletion
SAP BEx -Denial of Service and Arbitrary Favorites Modification/Deletion Impact on Business An authenticated attacker can cause a denial-of-service condition for other users, preventing them from accessing the system via the SAP GUI. Additionally, the attacker can modify or delete user-specific favorite nodes, leading to operational disruption and loss of convenience features for the affected…
03/13/2026
Denial of Service and Arbitrary Favorites Modification/Deletion
Denial of Service and Arbitrary Favorites Modification/Deletion Impact on Business An authenticated attacker can cause a denial-of-service condition for other users, preventing them from accessing the system via the SAP GUI. Additionally, the attacker can modify or delete user-specific favorite nodes, leading to operational disruption and loss of convenience features for the affected business users….
09/10/2025
Denial of service (DOS) in SAP NetWeaver and ABAP platform
Denial of service (DOS) in SAP NetWeaver and ABAP platform! Impact on Business A remote attacker can block all work processes of an SAP System running on SAP NetWeaver AS ABAP. This has a very high negative impact on the availability of the system and its business applications. Vulnerability Details A certain remote-enabled function module, from /SDF/EWA…
09/10/2025
Missing Authorization Check in SAP Production and Revenue Accounting
Missing Authorization Check in SAP Production and Revenue Accounting Impact on Business Successful exploitation of the vulnerability gives the attacker useful information that can be used in espionage campaigns or in building different exploitation chains based on it. This has a high impact on the confidentiality of the system and its business applications. Vulnerability Details A certain remote-enabled…
