SAP S/4HANA SQL Injection Vulnerability in Remote-Enabled Function Module

Vulnerability

A SQL injection vulnerability has been identified in SAP S/4HANA (On-Premise) within a remote-enabled function module component. This vulnerability could be exploited by an authenticated attacker to execute unauthorized database queries, potentially exposing sensitive information that should otherwise remain confidential. The flaw significantly impacts data confidentiality, with no effects on the application's integrity or availability.

Impact

Exploitation of this vulnerability could lead to unauthorized database access and query execution, allowing attackers to access sensitive information improperly.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, specifically on SAP Security Patch Days, which occur on the second Tuesday of each month.

Added: Jun 9, 2026, 1:26 AM
Updated: Jun 9, 2026, 1:26 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
4.9
remediation
6.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.