Executive brief
SAP S/4HANA, a comprehensive enterprise resource planning suite, contains a security flaw in one of its internal communication modules. An authorized user with basic access could exploit this vulnerability to run unauthorized database queries and view sensitive business information. While this does not allow an attacker to delete data or crash the system, it poses a significant risk to data privacy and confidentiality.
Technical details
An SQL injection vulnerability (CWE-89) exists within a remote-enabled function module (RFM) in SAP S/4HANA (On-Premise). The flaw is caused by improper neutralization of special elements used in SQL commands, allowing an authenticated attacker with low privileges to bypass intended access controls. By sending crafted inputs to the affected module over the network, an attacker can execute arbitrary SQL queries against the backend database. This exploit primarily impacts data confidentiality, enabling unauthorized read access to sensitive records, though it does not provide a mechanism for data modification (integrity) or service disruption (availability). SAP has released security note 3751691 to address this issue.
Affected products
- SAP S/4HANA (On-Premise)
Timeline
- 2026-06-09: advisory: SAP Security Patch Day release
- 2026-06-09: disclosed: NVD publication date