SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.

07/30/2026

Open Redirection in SAP NetWeaver Application Server ABAP

Open Redirection in SAP NetWeaver Application Server ABAP Impact on Business An unauthenticated remote attacker can redirect users to arbitrary untrusted sites using a malicious link. Since the link initially points to a trusted server, phishing attempts are more likely to succeed, potentially leading to credential theft or other malicious actions against the victim. Vulnerability…

07/30/2026

SAP MDM Server – MDM Console Session Hijacking

SAP MDM Server – MDM Console Session Hijacking Impact on Business An unauthenticated remote attacker can hijack active sessions on the SAP MDM Console. This allows the attacker to access sensitive information, such as application logs and system details, and perform administrative actions, including the deletion of repositories. This vulnerability impacts the confidentiality, integrity, and…

07/30/2026

Reflected Cross-Site Scripting (XSS) in SAP NetWeaver

Reflected Cross-Site Scripting (XSS) in SAP NetWeaver Impact on Business Successful exploitation of this vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript code into the application. This code is executed within the victim’s browser session when they interact with a crafted URL. This can lead to session hijacking, redirection to malicious websites, defacement…

07/30/2026

Reflected Cross-Site Scripting (XSS) through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler

Reflected Cross-Site Scripting (XSS) through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler Impact on Business Successful exploitation of the identified vulnerability enables an attacker to run malicious scripts in the browser of end users. This could cause website defacement, phishing attacks, or unintended requests being delivered to the vulnerable application server on behalf…

07/30/2026

Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler

Memory Corruption and Information Leak through Server-Side Request Forgery (SSRF) in BIC Document HTTP Handler Impact on Business A remote, authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability to trigger memory corruption or an information leak. This can lead to the crashing of work processes, causing a high impact on system availability, and…

07/30/2026

Unauthenticated Java Deserialization in SAP SRM

Unauthenticated Java Deserialization in SAP SRM Impact on Business A remote, unauthenticated attacker can exploit a Java deserialization vulnerability in SAP Supplier Relationship Management (SRM). Successful exploitation could allow the attacker to execute arbitrary commands on the operating system with the privileges of the SAP Administrator (sidadm). This has a critical impact on the confidentiality,…

07/30/2026

Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network

Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network Impact on Business A remote, authenticated attacker with high privileges can exploit a Java deserialization vulnerability to execute arbitrary operating system commands. This can lead to a full compromise of the affected system, severely impacting the confidentiality, integrity, and availability of the…

07/30/2026

SAP NetWeaver AS Java ILM Data Archiving Service Insecure Deserialization

SAP NetWeaver AS Java ILM Data Archiving Service Insecure Deserialization Impact on Business An authenticated attacker with high privileges can exploit this vulnerability to execute arbitrary operating system commands on the server. This could lead to a full compromise of the affected system, significantly impacting the confidentiality, integrity, and availability of the business application and…

07/30/2026

SAP Netweaver JAVA – Log Viewer – Insecure JAVA Deserialization

SAP Netweaver JAVA – Log Viewer – Insecure JAVA Deserialization Impact on Business Successful exploitation of this vulnerability can fully compromise the SAP system. An authenticated attacker with high privileges could execute arbitrary OS commands, leading to a complete compromise of confidentiality, integrity, and availability of the affected system and its business applications. Vulnerability Details…

Page 5 of 35