SQL Injection vulnerability in SAP S/4HANA
Summary
| CVE | CVE-2026-44744 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-09 01:16:46 UTC |
| Updated | 2026-06-09 02:08:28 UTC |
| Description | SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The vulnerability has a high impact on the confidentiality of the data with no impact on the integrity and availability of the application. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.002240000 probability, percentile 0.127820000 (date 2026-06-15)
Problem Types: CWE-89 | CWE-89 CWE-89: Improper Neutralization of Special Elements used in an SQL Command
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP SE | SAP S/4HANA | affected S4FND 102 | Not specified |
| CNA | SAP SE | SAP S/4HANA | affected 103 | Not specified |
| CNA | SAP SE | SAP S/4HANA | affected 104 | Not specified |
| CNA | SAP SE | SAP S/4HANA | affected 105 | Not specified |
| CNA | SAP SE | SAP S/4HANA | affected 106 | Not specified |
| CNA | SAP SE | SAP S/4HANA | affected 107 | Not specified |
| CNA | SAP SE | SAP S/4HANA | affected 108 | Not specified |
| CNA | SAP SE | SAP S/4HANA | affected 109 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| me.sap.com/notes/3751691 | [email protected] | me.sap.com | |
| url.sap/sapsecuritypatchday | [email protected] | url.sap | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.