SAP S/4HANA
cpe:2.3:a:sap:s/4_hana:*:*:*:*:*:*:*, +2 more
A SQL injection vulnerability has been identified in SAP S/4HANA (On-Premise) within a remote-enabled function module component. This vulnerability could be exploited by an authenticated attacker to execute unauthorized database queries, potentially exposing sensitive information that should otherwise remain confidential. The flaw significantly impacts data confidentiality, with no effects on the application's integrity or availability.
Exploitation of this vulnerability could lead to unauthorized database access and query execution, allowing attackers to access sensitive information improperly.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, specifically on SAP Security Patch Days, which occur on the second Tuesday of each month.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.