SAP Landscape Transformation RFC Function Module ABAP Code Injection Vulnerability

Vulnerability

A vulnerability exists in SAP Landscape Transformation within an RFC-exposed function module, allowing a high-privileged adversary to inject arbitrary ABAP code and operating system commands. This could lead to unauthorized modifications of information, although the attacker would not have control over the type or extent of these changes. As a result, there is a low impact on integrity, while confidentiality and availability remain unaffected.

Impact

Exploitation of this vulnerability could result in unauthorized injection of ABAP code and operating system commands, potentially leading to unauthorized modifications of information.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, specifically on the SAP Security Patch Day.

Added: Apr 14, 2026, 12:26 AM
Updated: Apr 14, 2026, 12:26 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.4
remediation
6.0
relevance
5.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.