Executive brief
SAP Social Intelligence contains an SQL injection vulnerability that allows authenticated attackers to inject malicious SQL commands directly into the database without additional authorization checks. Exploitation could allow attackers to modify database structure and compromise the confidentiality, integrity, and availability of the system and data stored within it.
Technical details
This is an SQL injection vulnerability (specifically SQL DDL injection) in SAP Social Intelligence that requires prior authentication to exploit. The vulnerable component fails to properly sanitize SQL input, allowing an authenticated attacker to inject Data Definition Language (DDL) statements into database queries. An attacker with valid credentials can directly modify database structure and objects. The vulnerability has a CVSS score of 6.3 (medium severity) and patches are available via SAP Security Patch Day.
Affected products
- SAP Social Intelligence
Timeline
- 2026-08-11: disclosed