VDB
CVE-2026-0507
CVE-2026-0507
PUBLISHED
CVSS 8.399999618530273 HIGH
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating system commands. Successful exploitation could lead to full compromise of the system�s confidentiality, integrity, and availability.
EPSS 1.37% · 80.6th percentile
Risk Scores
CVSS 3.1
8.399999618530273
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
1.37%
80.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP | Wily Introscope Enterprise Manager | |
| SAP | HANA database | |
| SAP | ERP Central Component and S/4HANA | |
| SAP | Landscape Transformation | |
| SAP | S/4HANA Private Cloud and On-Premise | |
| SAP | Application Server for ABAP and NetWeaver RFCSDK | |
| SAP | S/4HANA | |
| SAP | Business Server Pages Application | |
| SAP | Fiori App | |
| SAP | Supplier Relationship Management | |
| SAP | NetWeaver Enterprise Portal | |
| SAP | Identity Management | |
| SAP_SE | SAP Application Server for ABAP and SAP NetWeaver RFCSDK | 7.77, 7.89, 7.93 |
| SAP | Business Connector | |
| SAP | NetWeaver Application Server ABAP et ABAP Platform |
Timeline
- Jan 13, 2026 EPSS Score
- Jan 13, 2026 CVE Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 16, 2026 EPSS Score
- Jan 19, 2026 EPSS Score
- Jan 22, 2026 EPSS Score