CVE-2018-2494: SAP Business Application Software Integrated Solution

High severity, CVSS 8.0. EPSS: 0.8% chance of exploitation in the next 30 days.

Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.

Affected products

  • SAP Business Application Software Integrated Solution: from 7.00, up to and including 7.02; from 7.10, up to and including 7.30; from 7.50, up to and including 7.53; version 7.31 only; version 7.40 only

Published 2018-12-11. Last modified 2026-06-17.