Impact
SAP S/4HANA (On‑Premise) contains a SQL injection flaw in a remote‑enabled function module component, allowing an authenticated attacker to embed malicious SQL and retrieve database information that is not normally accessible. The vulnerability is a classic CWE‑89 flaw that directly compromises data confidentiality; it does not alter data integrity or impact application availability. This can enable the attacker to execute arbitrary queries and exfiltrate sensitive business data.
Affected Systems
The flaw affects SAP S/4HANA On‑Premise deployments. No specific product versions are listed in the advisory, so all installations using the affected function module component are potentially vulnerable.
Risk and Exploitability
With a CVSS score of 6.5 the flaw represents moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that it has not yet been widely exploited in the wild. Nevertheless, the attack requires the attacker to be authenticated and to have permission to invoke the vulnerable function module; once access is achieved, the attacker can perform unauthorized database queries. The risk is tangible for organizations that have not applied the vendor’s patch or mitigated the exposure via access controls.
OpenCVE Enrichment