Impact
The vulnerability is an SQL injection flaw in SAP S/4HANA Private Cloud and On‑Premise (Financials – General Ledger). Because the application fails to validate input, an authenticated user can inject arbitrary SQL. The attacker could read, alter, or delete backend database records, compromising confidentiality, integrity, and availability of financial data, with system‑wide impact for any user possessing valid credentials.
Affected Systems
SAP's S/4HANA Private Cloud and On‑Premise deployments that use the Financials – General Ledger module are affected. No specific version range is documented in the CNA data, so all installations of these products are potentially vulnerable unless a patch has been applied.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, but the EPSS score of less than 1% suggests that exploitation attempts are unlikely at this time. The vulnerability is not listed in KEV, meaning no confirmed active exploits are available. Attackers would need authenticated access to the application and specific knowledge of the database schema to craft effective payloads, which limits the likelihood of successful exploitation despite the high impact of a successful attack.
OpenCVE Enrichment