Junglewise Threat Intelligence

CVE-2026-44769: SAP S/4HANA Project Management SQL injection in PPM-PRO

CVE-2026-44769 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Vendors: SAP.

Executive brief

SAP S/4HANA Project Management is a tool used by organizations to manage large-scale projects and portfolios. A security vulnerability has been identified that allows a highly privileged user to run unauthorized database queries. While this could lead to the exposure of some backend data, the overall impact on the system's integrity and availability is considered low.

Technical details

This vulnerability is classified as an SQL injection (CWE-89) within the SAP S/4HANA Project Management (PPM-PRO) component. An attacker with high privileges can bypass intended query restrictions to execute crafted SQL commands against the backend database. The attack vector is over the network, but it requires high privileges and involves high complexity (AC:H). Successful exploitation allows for unauthorized reading of database information, though SAP notes the impact on integrity and availability is low. The issue is addressed in SAP Security Note 3537373.

Affected products

  • SAP S/4HANA Project Management (PPM-PRO) SAP_APPL 600, 602, 603, 604, 605, 606, 617, 618; S4CORE 102, 103, 104, 105, 106, 107, 108; CPRXRPM 400, 450_700, 500_702, 610_740

Timeline

  • 2026-07-14: advisory: Initial publication by SAP and NVD

References