SAP S/4HANA Private Cloud and On-Premise SQL Injection Vulnerability in Financials General Ledger

Vulnerability

A vulnerability exists in SAP S/4HANA Private Cloud and On-Premise versions of Financials General Ledger, where insufficient input validation allows authenticated users to execute crafted SQL queries. This exploitation could lead to unauthorized reading, modification, and deletion of backend database data, significantly impacting the application's confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability could result in unauthorized access to database information, allowing for reading, modifying, or deleting data. Such actions could disrupt the application's normal functioning and data integrity.

Remediation

Users are advised to consult the SAP Security Notes for guidance on applying necessary patches. SAP Security Patch Day occurs on the second Tuesday of each month, and details can be found in the SAP Security Patch Day Bulletin.

Added: Jan 13, 2026, 2:27 AM
Updated: Jan 13, 2026, 2:27 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.9
remediation
0.0
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.