Sap Basis
Vendor:
First CVE: Oct 5, 2016 · Active for 9 years
18
Total CVEs
More Total CVEs than 94% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sap Basis over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2016
9 years ago
Most Recent CVE
Feb 10, 2026
168 days ago
CVE Severity & Scoring
Sap Basis18 CVEs
67%
28%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required3 (16.7%)
Privileges Required
Low11 (61.1%)
High2 (11.1%)
None5 (27.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23687HIGH SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML docume | Feb 10, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-0066HIGH Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access contr | Jan 14, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-0063HIGH SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges t | Jan 14, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-34687CRITICAL SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
An attacker ca | May 14, 2024 | 9.0 | 27 | NO | NO |
CVE-2016-4551HIGH The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vect | Oct 5, 2016 | 7.5 | 25 | NO | NO |
CVE-2025-23193HIGH SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, po | Feb 11, 2025 | 7.5 | 21 | NO | NO |
CVE-2026-0484MEDIUM Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text | Feb 10, 2026 | 6.5 | 20 | NO | NO |
CVE-2025-0058MEDIUM In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information t | Jan 14, 2025 | 6.5 | 19 | NO | NO |
CVE-2026-24312MEDIUM An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions | Feb 10, 2026 | 5.2 | 18 | NO | NO |
CVE-2025-42911MEDIUM SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operat | Sep 9, 2025 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Sap Basis
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 918 | 1 | 8.8 | 0.5% | 0 | 0 |
| 917 | 1 | 8.8 | 0.5% | 0 | 0 |
| 916 | 1 | 8.8 | 0.5% | 0 | 0 |
| 914 | 2 | 7.7 | 0.4% | 0 | 0 |
| 913 | 2 | 7.7 | 0.4% | 0 | 0 |
| 912 | 2 | 7.7 | 0.4% | 0 | 0 |
| 816 | 6 | 5.3 | 0.2% | 0 | 0 |
| 804 | 1 | 8.8 | 0.5% | 0 | 0 |
| 796 | 2 | 6.8 | 0.4% | 0 | 0 |
| 795 | 2 | 6.8 | 0.4% | 0 | 0 |
| 758 | 15 | 6.4 | 0.3% | 0 | 0 |
| 757 | 16 | 6.3 | 0.3% | 0 | 0 |
| 756 | 16 | 6.3 | 0.3% | 0 | 0 |
| 755 | 16 | 6.3 | 0.3% | 0 | 0 |
| 754 | 17 | 6.2 | 0.3% | 0 | 0 |
| 753 | 17 | 6.2 | 0.3% | 0 | 0 |
| 752 | 16 | 6.2 | 0.3% | 0 | 0 |
| 751 | 15 | 6.3 | 0.3% | 0 | 0 |
| 750 | 15 | 6.3 | 0.3% | 0 | 0 |
| 740 | 15 | 6.3 | 0.3% | 0 | 0 |