medium2026-06-09SAP S/4HANACVE-2026-44744

SQL Injection in SAP S/4HANA Self-Service Procurement

SAP S/4HANA (Self-Service Procurement)

Our Take

SQL injection in a remote-enabled function module is inherently more exploitable than a local-only vulnerability. Procurement data manipulation has direct financial and audit implications. Include in your next planned window.

Vulnerability Detail

SQL injection vulnerability in a remote-enabled function module within the SAP S/4HANA Self-Service Procurement component. An authenticated attacker can inject SQL statements through unsanitised input, potentially accessing or modifying procurement data beyond their authorisation.

Patch Action

Apply SAP Note 3751691. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

6.5

SAP Note

3751691

CVE

CVE-2026-44744

Published

2026-06-09

← All patches