By exploiting this vulnerability, an unauthenticated attacker could inject malicious code in the back-office application to get or modify information systems.
Please fill out the form to download the security advisory.
Further Reading
Missing Authorization Check in SSC_E2E_STORE_BDCDATA
Onapsis Security Advisory 2026-0091: Missing Authorization Check in SSC_E2E_STORE_BDCDATA Impact on Business A remote, authenticated attacker can exploit a missing authorization check to insert arbitrary records into the INDX database table. This vulnerability has a low impact on the integrity of the system and its business applications. Vulnerability Details The remote-enabled function module SSC_E2E_STORE_BDCDATA within…
SAP BEx -Denial of Service and Arbitrary Favorites Modification/Deletion
SAP BEx -Denial of Service and Arbitrary Favorites Modification/Deletion Impact on Business An authenticated attacker can cause a denial-of-service condition for other users, preventing them from accessing the system via the SAP GUI. Additionally, the attacker can modify or delete user-specific favorite nodes, leading to operational disruption and loss of convenience features for the affected…
Denial of Service and Arbitrary Favorites Modification/Deletion
Denial of Service and Arbitrary Favorites Modification/Deletion Impact on Business An authenticated attacker can cause a denial-of-service condition for other users, preventing them from accessing the system via the SAP GUI. Additionally, the attacker can modify or delete user-specific favorite nodes, leading to operational disruption and loss of convenience features for the affected business users….
