CVE-2019-0349: SAP Advanced Business Application Programming Platform Kernel

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute “Go to statement” without possessing the authorization S_DEVELOP DEBUG 02, resulting in Missing Authorization Check

Affected products

  • SAP Advanced Business Application Programming Platform Kernel: version 7.21 only; version 7.21ext only; version 7.22 only; version 7.22ext only; version 7.49 only; version 7.53 only; …

Published 2019-08-14. Last modified 2026-06-17.