CVE-2017-16682: SAP Business Application Software Integrated Solution

High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.

SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.

Affected products

  • SAP Business Application Software Integrated Solution: from 7.00, up to and including 7.02; from 7.50, up to and including 7.52; version 7.30 only; version 7.31 only; version 7.40 only
  • SAP NetWeaver Internet Transaction Server: affected versions not specified

Published 2017-12-12. Last modified 2026-06-17.