CVE-2019-0248: SAP Basis

Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.

Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted.

Affected products

  • SAP Basis: version 7.5 only
  • SAP NetWeaver: version 7.5 only; version 7.51 only; version 7.52 only; version 7.53 only

Published 2019-01-08. Last modified 2026-06-17.