PT-2026-2337 · Sap · Sap S/4Hana

CVE-2026-0501

·

Publicado

2026-01-13

·

Atualizado

2026-02-10

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger) (affected versions not specified)
Description The issue stems from inadequate input validation within the SAP S/4HANA Financials General Ledger component. An authenticated user can potentially execute specially crafted SQL queries, enabling them to read, modify, and delete data within the backend database. This could compromise the confidentiality, integrity, and availability of the application. The vulnerability allows for full database access. It is noted that Shodan bots may identify vulnerable instances before administrators are aware of their version.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00368
CVE-2026-0501

Produtos afetados

Sap S/4Hana