$ techbeacon▋
CVE & Exploits

Onapsis Calls for Immediate Patch Deployment as SAP’s ‘Overpass’ Bug Scores Perfect 10

Onapsis Calls for Immediate Patch Deployment as SAP’s ‘Overpass’ Bug Scores Perfect 10

Security firm Onapsis has issued an urgent advisory to organizations that run SAP software, urging them to install patches that address a newly disclosed vulnerability known as “Overpass.” The flaw has been assigned a CVSS (Common Vulnerability Scoring System) rating of 10.0, the highest possible score, indicating that successful exploitation could have catastrophic consequences.

According to the advisory, Overpass is a critical weakness embedded in core SAP components that could enable an unauthenticated attacker to execute arbitrary code on vulnerable systems. While the technical details remain limited in public disclosures, the severity rating reflects the potential for full system compromise, data exfiltration, and disruption of business‑critical processes.

SAP’s enterprise resource planning (ERP) suite powers the back‑office operations of thousands of corporations worldwide, spanning finance, supply chain, human resources, and more. A breach of such a central platform can ripple across entire organizations, exposing sensitive financial records, intellectual property, and personal data. The high‑impact nature of the Overpass bug therefore raises alarms not only for SAP’s direct customers but also for the broader ecosystem of partners and third‑party applications that integrate with its services.

The warning was first reported by Infosecurity Magazine, which highlighted Onapsis’s recommendation that all SAP installations apply the vendor‑provided remediation without delay. Onapsis, a specialist in securing SAP and Oracle environments, regularly monitors threat intelligence for vulnerabilities that could affect critical business systems. Its advisory underscores the urgency of the situation, noting that the exploitability of Overpass appears to be straightforward and that no public proof‑of‑concept code has yet surfaced.

Onapsis advises customers to follow a three‑step approach: verify that the latest SAP security patches are downloaded, test the updates in a controlled environment to ensure compatibility with custom extensions, and then deploy the fixes across production systems. Organizations are also encouraged to review access controls, monitor for anomalous activity, and maintain an up‑to‑date inventory of all SAP instances to reduce the attack surface.

Industry analysts expect that SAP will continue to release additional guidance and possibly further hot‑fixes as more information about Overpass emerges. Failure to remediate promptly could leave enterprises vulnerable to sophisticated threat actors who routinely target high‑value ERP platforms. As the situation develops, security teams are likely to prioritize the Overpass patch alongside other critical updates, reinforcing the broader push for rigorous vulnerability management in the era of increasingly complex supply‑chain attacks.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related