CVE-2016-9832: Pwc Ace-Advanced Business Application Programming

Critical severity, CVSS 9.9. EPSS: 4% chance of exploitation in the next 30 days.

PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS, as demonstrated by WEBGUI or Report.

Affected products

  • Pwc Ace-Advanced Business Application Programming: version 8.10.304 only

Published 2016-12-10. Last modified 2026-06-17.