A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when a new user session opens and travels via communication protocols like RFC (Remote Function Call) and HTTP from the client to the server. Onapsis explained that, because EPP processing is shared kernel code, the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another. The bug is remotely exploitable without authentication and exists by default in a range of SAP components. Successful exploitation of this vulnerability may allow a remote attacker to run arbitrary operating system commands on the SAP host with SAP administrative privileges, leading to a total compromise of the underlying SAP business data and processes.