PT-2026-2337 · Sap · Sap S/4Hana
Published
2026-01-13
·
Updated
2026-02-10
·
CVE-2026-0501
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger) (affected versions not specified)
Description
The issue stems from inadequate input validation within the SAP S/4HANA Financials General Ledger component. An authenticated user can potentially execute specially crafted SQL queries, enabling them to read, modify, and delete data within the backend database. This could compromise the confidentiality, integrity, and availability of the application. The vulnerability allows for full database access. It is noted that Shodan bots may identify vulnerable instances before administrators are aware of their version.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap S/4Hana