medium2026-06-09SAP BW/4HANACVE-2026-44754
Missing Caller ID Check in SAP BW Operational Data Provisioning APIs
SAP BW/4HANA and BW on HANA (ODP APIs)
Our Take
ODP is the backbone of SAP's modern data extraction architecture — it feeds BW, CDS views, and third-party data pipelines. Unauthorised access to ODP APIs is a data governance and compliance concern as much as a security one. Next planned window.
Vulnerability Detail
A missing caller identification check in the Operational Data Provisioning (ODP) APIs of SAP BW/4HANA and BW on HANA allows an authenticated attacker to invoke ODP APIs without proper caller verification, potentially accessing or manipulating data extraction pipelines and underlying data sources.
Patch Action
Apply SAP Note 3748819. Verify affected versions in the official SAP Note.
Patch Info