Impact
The vulnerability allows an attacker with high privileges to craft and execute arbitrary SQL queries against the backend database of SAP S/4HANA Project Management (PPM-PRO). The flaw is a classic SQL injection that fails to properly sanitize input, as classified by CWE-89. While the database content can be exposed, the description indicates that integrity and availability are not affected, resulting in a low impact on confidentiality.
Affected Systems
This issue affects SAP S/4HANA Project Management (PPM-PRO). No specific version numbers are listed in the CVE data, so the scope may include all released versions that contain the vulnerable code path. The flaw requires the attacker to possess high‑privilege access within the application.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity. The EPSS score of less than 1% points to a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an authenticated insider or a compromised high‑privilege user, rather than an external remote attacker. The risk to confidentiality exists only for sensitive data that might be queried by the attacker, whereas integrity and availability remain unaffected.
OpenCVE Enrichment