CVE-2017-6950: SAP GUI For Windows

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.

Affected products

  • SAP GUI For Windows: version 7.20 only; version 7.30 only; version 7.40_core_sp00-sp011 only; version 7.50_core_sp000 only

Published 2017-03-23. Last modified 2026-06-17.