Impact
The vulnerability allows an authenticated user to exploit a flaw in a generic function module call within SAP CRM and SAP S/4HANA’s Scripting Editor, enabling execution of arbitrary SQL statements. This results in a full compromise of the underlying database, causing severe loss of confidentiality, integrity, and availability.
Affected Systems
Affected products include SAP CRM and SAP S/4HANA (Scripting Editor) from SAP. No specific version range is listed in the available data; therefore all releases that contain the Scripting Editor component remain under consideration.
Risk and Exploitability
The flaw carries a CVSS score of 9.9, indicating critical severity. EPSS indicates a low exploitation probability, with a score of less than 1 percent. The vulnerability is not yet listed in the CISA KEV catalog. The attack requires authenticated access to the system, meaning an attacker must possess valid credentials or compromise an existing user account. If exploited, the attacker can gain complete control over the database, elevating the risk dramatically for systems that host sensitive data and rely on the affected components.
OpenCVE Enrichment