Skip to content
Threat Feed
high advisory

Remote Code Execution Vulnerability in SAP Extended Passport Processing

A critical unauthenticated remote code execution vulnerability in the SAP Extended Passport (EPP) kernel component allows attackers to execute arbitrary system commands via RFC or HTTP communication layers.

Researchers have identified a critical vulnerability within SAP Extended Passport (EPP) processing, a core kernel mechanism utilized across the SAP ecosystem for tracing and monitoring end-to-end communication. EPP data structures are generated automatically upon the initiation of user sessions and traverse distributed landscapes via communication protocols including RFC (Remote Function Call) and HTTP. Because this EPP processing logic is embedded within the SAP Kernel, the vulnerability is accessible to unauthenticated attackers through the SAP GUI layer or via inter-system RFC links. This allows for remote exploitation without prior authentication. Successful execution leads to the compromise of the underlying SAP host, as the attacker gains the ability to run arbitrary operating system commands with SAP administrative privileges. This vulnerability affects a broad range of SAP components and poses a significant risk of total data and process compromise for organizations running affected SAP environments.

Impact

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to achieve full system compromise. By gaining the ability to execute arbitrary OS commands with administrative privileges, an attacker can exfiltrate sensitive business data, manipulate core enterprise processes, and pivot deeper into the target organization's internal network. This threat is particularly critical due to the ubiquitous nature of the affected SAP Kernel code across both SAP and non-SAP interconnected landscapes.

Recommendation

Prioritize the identification of internet-facing SAP components. Monitor SAP logs for anomalous RFC and HTTP traffic patterns originating from unauthorized or external network ranges. Engage with SAP support to obtain and apply the necessary kernel patches to address the EPP processing vulnerability.


Immediate actions

Inventory all internet-facing SAP infrastructure.

IT Operations 24h

Mitigations

Monitor vendor security portal for SAP kernel patches addressing EPP processing.

immediate IT Operations

SAP Kernel vulnerability