SAP S/4HANA Frontend OData Service Authorization Vulnerability Allowing Unauthorized Entity Modification

Vulnerability

A vulnerability exists in the SAP S/4HANA frontend OData Service 'Manage Reference Structures' due to inadequate authorization checks. This flaw enables an attacker to update and delete child entities through the exposed OData services without proper authorization. The vulnerability significantly compromises data integrity, while leaving confidentiality and availability unaffected.

Impact

Exploitation of this vulnerability allows for unauthorized updates and deletions of child entities via the affected OData service, leading to a high impact on data integrity.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.

Added: Apr 14, 2026, 12:23 AM
Updated: Apr 14, 2026, 12:23 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
7.0
remediation
8.3
relevance
5.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.