Executive brief
SAP S/4HANA Enterprise Search, a tool used to find and access business data across the enterprise, contains a critical security flaw. An authenticated user can execute unauthorized database commands, potentially allowing them to steal sensitive corporate information or crash the system entirely. This could lead to significant data breaches and disruption of business operations.
Technical details
A SQL injection vulnerability exists in SAP S/4HANA Enterprise Search for ABAP due to improper neutralization of special elements in SQL commands (CWE-89). The application directly concatenates user-controlled input into SQL queries without sufficient validation or sanitization. An authenticated attacker with low privileges can exploit this over the network to execute arbitrary SQL statements against the underlying database. Successful exploitation can lead to unauthorized access to sensitive data (High Confidentiality impact) or a denial-of-service condition by crashing the application (High Availability impact). The vulnerability is addressed in SAP Security Note 3724838.
Affected products
- SAP S/4HANA (Enterprise Search for ABAP)
Timeline
- 2026-05-12: advisory: SAP published security note 3724838 during the May 2026 Patch Day.