SAP @sap/hdi-deploy Package SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the SAP @sap/hdi-deploy package. This issue arises because SQL queries are generated dynamically using user input, lacking proper parameterization or the use of prepared statements. If exploited, this vulnerability could allow high-privileged users to modify SELECT statements, thereby affecting the application's confidentiality and availability, although integrity remains unaffected.

Impact

Exploitation of this vulnerability could lead to unauthorized alterations of SQL queries, potentially compromising the application's confidentiality and availability.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.

Added: May 12, 2026, 3:25 AM
Updated: May 12, 2026, 3:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.