SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.

08/05/2026

SAP Software Update Manager (SUM) – Credential Exposure Through Log Files

SAP Software Update Manager (SUM) – Credential Exposure Through Log Files Impact on Business A local attacker with low privileges can retrieve sensitive credentials, such as database or SAP administrator passwords, from log files. This has a high impact on the confidentiality of the system and could allow the attacker to escalate privileges within the…

08/05/2026

Missing Authorization Check in RFC Enabled Function Module RSWR_DB_DATA_DELETE

Missing Authorization Check in RFC Enabled Function Module RSWR_DB_DATA_DELETE Impact on Business An authenticated attacker could delete data from the RSWR_DATA table, which stores runtime data for user personalization and bookmarks in the Business Explorer (BEx) tool. This could lead to the loss of user-specific configurations, metrics, and a decrease in user productivity within the…

08/05/2026

Missing Authorization Check in SAP NetWeaver

Missing Authorization Check in SAP NetWeaver Impact on Business A remote attacker with low privileges can enumerate all users in the current system client. This information disclosure aids in gathering valid usernames which could be used in subsequent attacks, such as password brute-forcing or social engineering, potentially increasing the attack surface of the system. Vulnerability…

08/05/2026

Missing Authorization and Information Disclosure in SAP Business Warehouse

Missing Authorization and Information Disclosure in SAP Business Warehouse Impact on Business A remote attacker can retrieve detailed configuration information about the SAP system and the underlying operating system. This information disclosure could aid an attacker in planning further attacks by identifying specific versions and configurations of the target environment. Vulnerability Details The remote-enabled function…

07/30/2026

Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST

Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST Impact on Business A remote authenticated attacker can discover detailed information about installed software components and their versions on the application server. This information disclosure aids in fingerprinting the system, potentially facilitating further attacks by identifying specific vulnerable components. This has a low impact…

07/30/2026

Missing Authorization Check in SAP ST-PI

Missing Authorization Check in SAP ST-PI Impact on Business A remote attacker can obtain sensitive information such as installed components, versions, patches, and user IDs from the application server. This information can be used to fingerprint the system and plan further attacks, impacting the confidentiality of the system. Vulnerability Details The remote-enabled function module /SDF/SWCM_GET_SYSTEM_INFO…

07/30/2026

Missing Authorization Check in RFC Enabled Function /BDL/_READ_LOG

Missing Authorization Check in RFC Enabled Function /BDL/_READ_LOG Impact on Business A remote authenticated attacker can read log messages and specific fields, such as usernames, from the application server. This has a low impact on the confidentiality of the system and its business applications. Vulnerability Details The remote-enabled function module /BDL/_READ_LOG allows authenticated users to…

07/30/2026

Missing Authorization Check and Information Disclosure in RFC enabled function AGS_SMT_TSAT_READ_SW_INFO

Missing Authorization Check and Information Disclosure in RFC enabled function AGS_SMT_TSAT_READ_SW_INFO Impact on Business A remote attacker can retrieve a list of installed software components and their versions from the affected system. This information disclosure could aid an attacker in identifying specific component versions to target in further attacks, potentially increasing the risk of successful…

07/30/2026

SAP SRM – XSS in SRM Live Auction

SAP SRM – XSS in SRM Live Auction Impact on Business A successful Cross-Site Scripting (XSS) attack could allow an unauthenticated attacker to hijack user sessions or force victims to perform unintended actions within the SAP SRM system. This can lead to unauthorized access and potential manipulation of business data, impacting the confidentiality and integrity…

Page 3 of 35