Business Connector
7 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Business Connector. Use it to gauge the current risk picture and drill into individual advisories.
Business Connector CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 4 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Medium7
Latest CVEs
The 7 most recently published vulnerabilities affecting Business Connector.
- CVE-2026-0514Cross-Site Scripting (XSS) vulnerability in SAP Business Connector6.1
- CVE-2025-42894Path Traversal vulnerability in SAP Business Connector6.8
- CVE-2025-42893Open Redirect vulnerability in SAP Business Connector6.1
- CVE-2025-42892OS Command Injection vulnerability in SAP Business Connector6.8
- CVE-2025-42886Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector6.1
- CVE-2006-0731WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the UR...4.0
- CVE-2006-0732Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or ...6.4
Product grouping is registry-driven, with AI assist and human review. How it works