SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.
07/30/2026
Arbitrary File Read in SAP SRM
Arbitrary File Read in SAP SRM Impact on Business An unauthenticated remote attacker can exploit this vulnerability to read arbitrary files from the operating system of the affected SAP server. This can lead to the disclosure of highly sensitive information, including system credentials and configuration files, which could be leveraged to further compromise the system…
07/30/2026
SAP SRM – Open Redirect in SRM Live Auction
SAP SRM – Open Redirect in SRM Live Auction Impact on Business An open redirect vulnerability in SAP Supplier Relationship Management allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. A successful attack can lead to various types of exploitation depending on the victim’s privileges, potentially impacting the integrity and…
07/30/2026
SAP SRM – Information Disclosure in SRM Live Auction
SAP SRM – Information Disclosure in SRM Live Auction Impact on Business An unauthenticated attacker can access sensitive system information over the network. This information disclosure could provide an attacker with details about the system’s configuration, versions, and environment, which could be used to plan further attacks. This has a low impact on the confidentiality…
07/30/2026
SAP SRM – XSS in tc | ~mdm | ~srmcat | ~uisearch
SAP SRM – XSS in tc\~mdm\~srmcat\~uisearch Impact on Business A successful Cross-Site Scripting (XSS) attack could allow an unauthenticated attacker to execute malicious scripts in the context of the victim’s browser. Depending on the victim’s privileges, this could lead to session hijacking or unauthorized actions performed on behalf of the user within the SAP SRM…
07/30/2026
SAP Netweaver JAVA – Information Disclosure in DispatchServlet
SAP Netweaver JAVA – Information Disclosure in DispatchServlet Impact on Business An unauthenticated attacker can retrieve a list of valid usernames from the affected SAP system. This information disclosure aids attackers in identifying valid accounts, which can be leveraged to facilitate further attacks such as brute-force attempts or social engineering campaigns, potentially compromising the system’s…
07/30/2026
SAP SRM – Blind XXE in /srm/messaging
SAP SRM – Blind XXE in /srm/messaging Impact on Business A remote, unauthenticated attacker can exploit this vulnerability to read arbitrary files from the file system of the application server. This has a high impact on the confidentiality of the system, potentially exposing sensitive business data, credentials, and system configurations. Additionally, it allows the attacker…
07/30/2026
Memory Corruption in SAP NetWeaver Master Data Management
Memory Corruption in SAP NetWeaver Master Data Management Impact on Business A remote unauthenticated attacker can cause a Denial of Service (DoS) condition in the SAP NetWeaver Master Data Management server. By exploiting this vulnerability, the attacker can terminate the service, rendering it unavailable for legitimate users and disrupting business processes. Vulnerability Details A memory…
07/30/2026
Memory Corruption in SAP NetWeaver Master Data Management
Memory Corruption in SAP NetWeaver Master Data Management Impact on Business An unauthenticated remote attacker can cause the SAP MDM Server to crash by sending a specially crafted packet. This results in a Denial of Service (DoS), rendering the system unavailable to legitimate users and disrupting business processes that rely on Master Data Management services….
07/30/2026
Missing Authorization Check in SSC_E2E_STORE_BDCDATA
Missing Authorization Check in SSC_E2E_STORE_BDCDATA Impact on Business A remote, authenticated attacker can exploit a missing authorization check to insert arbitrary records into the INDX database table. This vulnerability has a low impact on the integrity of the system and its business applications. Vulnerability Details The remote-enabled function module SSC_E2E_STORE_BDCDATA within the SAP S4 Foundation…
