"Additionally, reverse engineering the patch to create an exploit is relatively quick for SAP ABAP, since the ABAP code is open up to check out for everyone." The maximum-severity threat stems from a deserialization vulnerability. Serialization is actually a coding system that translates data constructions and object states into formats https://www.ecom-group.com/training-events/sap-bdc-introducing-sap-business-data-cloud-btp100/