Description
SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The vulnerability has a high impact on the confidentiality of the data with no impact on the integrity and availability of the application.
Published: 2026-06-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP S/4HANA (On‑Premise) contains a SQL injection flaw in a remote‑enabled function module component, allowing an authenticated attacker to embed malicious SQL and retrieve database information that is not normally accessible. The vulnerability is a classic CWE‑89 flaw that directly compromises data confidentiality; it does not alter data integrity or impact application availability. This can enable the attacker to execute arbitrary queries and exfiltrate sensitive business data.

Affected Systems

The flaw affects SAP S/4HANA On‑Premise deployments. No specific product versions are listed in the advisory, so all installations using the affected function module component are potentially vulnerable.

Risk and Exploitability

With a CVSS score of 6.5 the flaw represents moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that it has not yet been widely exploited in the wild. Nevertheless, the attack requires the attacker to be authenticated and to have permission to invoke the vulnerable function module; once access is achieved, the attacker can perform unauthorized database queries. The risk is tangible for organizations that have not applied the vendor’s patch or mitigated the exposure via access controls.

Generated by OpenCVE AI on June 9, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check SAP Security Note 3751691 and apply any recommended patch or upgrade for the affected function module
  • Limit user roles and permissions to ensure that only trusted accounts can call the vulnerable function module
  • If custom code or extensions are present, modify the queries to use parameterized statements or input validation to prevent injection
  • Configure and monitor SAP audit logs for abnormal SQL activity to detect exploitation attempts

Generated by OpenCVE AI on June 9, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap s/4hana
Vendors & Products Sap
Sap s/4hana

Tue, 09 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Description SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The vulnerability has a high impact on the confidentiality of the data with no impact on the integrity and availability of the application.
Title SQL Injection vulnerability in SAP S/4HANA
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-06-09T13:21:32.555Z

Reserved: 2026-05-07T18:16:34.194Z

Link: CVE-2026-44744

cve-icon Vulnrichment

Updated: 2026-06-09T13:21:28.699Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T01:16:46.333

Modified: 2026-06-09T02:08:28.150

Link: CVE-2026-44744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T08:56:27Z

Weaknesses