Sap Basis

Vendor:

First CVE: Oct 5, 2016 · Active for 9 years

18
Total CVEs
More Total CVEs than 94% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sap Basis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2016
9 years ago
Most Recent CVE
Feb 10, 2026
168 days ago

CVE Severity & Scoring

Sap Basis18 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required3 (16.7%)
Privileges Required
Low11 (61.1%)
High2 (11.1%)
None5 (27.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML docume
Feb 10, 20268.831NONO
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access contr
Jan 14, 20258.828NONO
SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges t
Jan 14, 20258.827NONO
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker ca
May 14, 20249.027NONO
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vect
Oct 5, 20167.525NONO
SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, po
Feb 11, 20257.521NONO
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text
Feb 10, 20266.520NONO
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information t
Jan 14, 20256.519NONO
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions
Feb 10, 20265.218NONO
SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operat
Sep 9, 20254.318NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Sap Basis

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
91818.80.5%00
91718.80.5%00
91618.80.5%00
91427.70.4%00
91327.70.4%00
91227.70.4%00
81665.30.2%00
80418.80.5%00
79626.80.4%00
79526.80.4%00
758156.40.3%00
757166.30.3%00
756166.30.3%00
755166.30.3%00
754176.20.3%00
753176.20.3%00
752166.20.3%00
751156.30.3%00
750156.30.3%00
740156.30.3%00