CVE-2026-0497: SAP SE Business Server Pages Application Product Designer Web UI

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

Affected products

  • SAP SE Business Server Pages Application Product Designer Web UI: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; …

Published 2026-01-13. Last modified 2026-06-17.