VendorsSAPbusiness_connectorall versions
Vulnerabilities

SAP Business Connector

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-42892
OS Command Injection vulnerability in SAP Business Connector
Published 2025-11-11 · Analyzed
6.8EPSS 0.008
CVE-2025-42894
Path Traversal vulnerability in SAP Business Connector
Published 2025-11-11 · Analyzed
6.8EPSS 0.003
CVE-2006-0732
Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the grace period has ended. NOTE: SAP Business Connector is an OEM version of webMethods Integration Server. webMethods states that this issue can only occur when the product is installed as root/admin, and if the attacker has access to a general purpose port; however, both are discouraged in the documentation. In addition, the attacker must already have acquired administrative privileges through other means.
Published 2006-02-16 · Modified
6.4EPSS 0.025
CVE-2025-42886
Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
Published 2025-11-11 · Analyzed
6.1EPSS 0.002
CVE-2025-42893
Open Redirect vulnerability in SAP Business Connector
Published 2025-11-11 · Analyzed
6.1EPSS 0.002
CVE-2026-0514
Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
Published 2026-01-13 · Analyzed
6.1EPSS 0.002
CVE-2006-0731
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
Published 2006-02-16 · Modified
4.03 PoCEPSS 0.027