SAP® Security Advisories

Onapsis Research Labs is the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.
09/17/2026
Missing authorization check in CRM_THTMLB_LOAD_CSS leads to arbitrary read of reports source code
Missing authorization check in CRM_THTMLB_LOAD_CSS leads to arbitrary read of reports source code Impact on Business A remote, authenticated attacker can read the source code of arbitrary reports from the application server. This has a low impact on the confidentiality of the system and its business applications, potentially exposing sensitive logic or information embedded in…
09/17/2026
Reflected XSS in BSP Application CRM_THTMLB_UTIL
Reflected XSS in BSP Application CRM_THTMLB_UTIL Impact on Business A remote attacker can exploit a Reflected Cross-Site Scripting (XSS) vulnerability to execute arbitrary JavaScript code in the victim’s browser. This can lead to the exfiltration of sensitive user information, unauthorized modifications to the system, or redirection to malicious websites, thereby impacting the confidentiality and integrity…
09/17/2026
SAP Netweaver JAVA Enterprise Portal – Translation Worklist Authentication Insecure Deserialization
SAP Netweaver JAVA Enterprise Portal – Translation Worklist Authentication Insecure Deserialization Impact on Business A remote, authenticated attacker can exploit an insecure deserialization vulnerability to execute arbitrary operating system commands on the target system. This has a critical impact on the confidentiality, integrity, and availability of the system and its business applications, potentially allowing full…
09/17/2026
SAP PO – SSRF with CR-LF injection in GRMG_WSRT
SAP PO – SSRF with CR-LF injection in GRMG_WSRT Impact on Business A remote, unauthenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability to send crafted HTTP requests from the vulnerable server. This could allow the attacker to discover internal open ports or access internal services, leading to a low impact on the confidentiality…
09/17/2026
SAP PO – Reflected XSS in PCC Xml Editor
SAP PO – Reflected XSS in PCC Xml Editor Impact on Business A successful attack could allow an unauthenticated attacker to hijack a user’s session or force the victim to perform undesired requests within the SAP Process Orchestration (PO) application. This can lead to unauthorized data access or modification, impacting the confidentiality and integrity of…
09/17/2026
SAP PO – User enumeration in GPWorkItemProvider
SAP PO – User enumeration in GPWorkItemProvider Impact on Business An unauthenticated remote attacker can enumerate valid usernames on the target SAP system. This has a low impact on the confidentiality of the system, but it allows an attacker to gather information about existing users and potentially identify configured services or applications, which could be…
09/17/2026
SAP PO – User enumeration in AuthorizationList
SAP PO – User enumeration in AuthorizationList Impact on Business Successful attacks impact the confidentiality of the SAP Process Orchestration (PO) system. An unauthenticated attacker can enumerate valid usernames, which allows them to extend their knowledge of the target environment. Furthermore, identifying the presence of specific technical users can reveal whether certain services or applications…
09/17/2026
SAP ADS – Download arbitrary file from PDF attachment
SAP ADS – Download arbitrary file from PDF attachment Impact on Business A highly privileged remote attacker can exploit this vulnerability to read arbitrary files from the file system of the application server. This has a high impact on the confidentiality of the system, as it allows access to critical information such as credentials and…
09/17/2026
SAP ADS – Download arbitrary file from customer fonts
SAP ADS – Download arbitrary file from customer fonts Impact on Business A remote, authenticated attacker with high privileges can read arbitrary files from the file system of the application server. This has a high impact on the confidentiality of the system, potentially exposing critical information and credentials to unauthorized parties. Vulnerability Details The SAP…
