SAP NetWeaver Feedback Notifications Service SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the SAP NetWeaver Feedback Notifications Service. This vulnerability allows authenticated attackers to inject arbitrary SQL code through user-controlled input fields. The application improperly validates or escapes these inputs, directly concatenating them into SQL queries. As a result, attackers can manipulate the WHERE clause logic, potentially gaining unauthorized access to or modifying database information. This vulnerability has a low impact on the application's confidentiality and availability, with no impact on integrity.

Impact

Exploitation of this vulnerability allows for SQL injection, enabling attackers to manipulate database queries. This could lead to unauthorized access to or modification of database information.

Remediation

Users are advised to consult the SAP Security Notes for guidance on applying patches or updates. SAP Security Notes can be accessed through the SAP for Me platform. For detailed information on the vulnerability and its implications, refer to the January 2026 SAP Security Patch Day Bulletin.

Added: Mar 10, 2026, 6:12 PM
Updated: Mar 10, 2026, 6:12 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
5.2
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.