CVE-2019-0270: SAP Advanced Business Application Programming Platform Kernel

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.74, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, 7.74, 8.04, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, 7.74, 7.75, 8.04.

Affected products

  • SAP Advanced Business Application Programming Platform Kernel: version 7.15 only; version 7.21 only; version 7.22 only; version 7.49 only; version 7.53 only; version 7.73 only; …
  • SAP Advanced Business Application Programming Platform KRNL32NUC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only
  • SAP Advanced Business Application Programming Platform KRNL32UC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only
  • SAP Advanced Business Application Programming Platform KRNL64NUC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only
  • SAP Advanced Business Application Programming Platform KRNL64UC: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only; version 7.49 only; version 7.73 only; …

Published 2019-03-12. Last modified 2026-06-17.