Security Advisories

The Onapsis Research Labs delivers regular SAP® and Oracle® vulnerability research to our ecosystem of customers, partners and the information security industry.

Onapsis security advisories enable customers to better understand the security and business implications of discovered SAP and Oracle security issues. This enables organizations to prioritize patches, updates and their remediation strategies to ensure continuity of the business. Onapsis security advisories, together with vendor patches and security notes, are available for download to provide vendors and end-users with the necessary information to mitigate advanced threats to mission-critical applications running on SAP and Oracle.

Critical
Oracle
07/28/2016
By exploiting this vulnerability, an unauthenticated attacker could achieve administrative rights and would be able to potentially compromise all information stored and processed on the JDE System.
Medium
Oracle
07/28/2016
By exploiting this vulnerability, an unauthenticated attacker could shut down the Server Manager.
Critical
Oracle
07/28/2016
By exploiting this vulnerability, an unauthenticated attacker could retrieve the administration user and passwords from the Server Manager. This could lead to a potential compromise of the entire JDE…
Critical
Oracle
07/28/2016
By exploiting this vulnerability, an unauthenticated attacker could create users in the Server Manager, ultimately compromising the entire JDE landscape and all of its information and processes.
High
Oracle
07/28/2016
By exploiting this vulnerability, an unauthenticated attacker could remotely shutdown the entire JD Edwards infrastructure.
07/20/2016
By exploiting this vulnerability, a remote unauthenticated attacker could access arbitrary business information from the SAP system.
07/20/2016
By exploiting this vulnerability, an unauthenticated attacker could access and modify any information indexed by the SAP system.
07/20/2016
By exploiting this vulnerability, a remote attacker may obtain clear-text passwords of SAP HANA users and get critical information.
Low
SAP
07/20/2016
By exploiting this vulnerability, an attacker could access business information indexed by the SAP system.
Medium
SAP
07/20/2016
By exploiting this vulnerability, a remote unauthenticated attacker could obtain technical information about the SAP HANA Platform that can be used to perform more complex attacks.
High
SAP
07/20/2016
By exploiting this vulnerability, an attacker could tamper the audit logs, hiding his evidence of an attack to a HANA system.
High
SAP
07/20/2016
By exploiting this vulnerability, an attacker could tamper the audit logs, hiding evidence of an attack to a HANA system.