Impact
The vulnerability is a string-based SQL injection that allows an authenticated attacker to insert DDL statements. This gives them the ability to alter the database schema, potentially deleting tables or adding malicious tables. Because the attacker must be authenticated, the attack would be carried out by an account that already has database privileges, and the changes can compromise confidentiality, integrity, and availability.
Affected Systems
The affected product is SAP Social Intelligence, as identified by the SAP SE CNA. The CVE note does not list specific version numbers, so all releases of SAP Social Intelligence in use should be considered potentially affected until a statement from SAP confirms the scope.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity. Because the EPSS score is not available and the vulnerability is not currently listed in KEV, the current likelihood of exploitation is uncertain, but the ability to modify database schema is significant. The attack requires an authenticated account with database access, and the possible impact is brittle but can be high if used to compromise confidentiality, integrity, or availability.
OpenCVE Enrichment