Impact
The vulnerability is a classic SQL Injection (CWE-89) in SAP S/4HANA Intercompany Matching and Reconciliation. A low‑privileged authenticated user can inject malicious input into certain functions that are then forwarded to the database unvalidated, enabling extraction of sensitive data. The result is a high‑impact compromise of confidentiality with no measurable effects on integrity or availability.
Affected Systems
Affected systems are SAP S/4HANA software versions supporting the Intercompany Matching and Reconciliation module. The specific version ranges are not listed in the vulnerability data, so any installation of this SAP product should be assumed at risk unless known to be patched. Users of this module should verify that they run the latest security updates from SAP.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS data is not available, and the issue is not recorded in CISA’s KEV catalog. An attacker would need to be authenticated at a low privilege level and craft malicious input into the application’s exposed interfaces. Once the injection succeeds the attacker gains read access to confidential database tables, which can be leveraged for further attacks or data exfiltration.
OpenCVE Enrichment