Executive brief
SAP S/4HANA (Private Cloud) relies on a third-party software component with a Regular Expression Denial of Service (ReDoS) vulnerability. An attacker without authentication can send specially crafted input that causes the system to consume excessive computational resources, making the service unavailable to legitimate users. This directly impacts business continuity and availability of critical ERP functionality.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in a third-party component used by SAP S/4HANA (Private Cloud). The attack is network-accessible and requires no authentication; an attacker can supply malicious input that triggers excessive processing within the affected regex pattern, exhausting system resources and causing denial of service. Successful exploitation results in high impact to service availability with no impact on confidentiality or integrity. Patches are available through SAP Security Notes; refer to SAP Note 3771065 and SAP Security Patch Day advisories for remediation guidance.
Affected products
- SAP S/4HANA Private Cloud
Timeline
- 2026-08-25: disclosed