medium2026-06-09SAP S/4HANACVE-2026-44744
SQL Injection in SAP S/4HANA Self-Service Procurement
SAP S/4HANA (Self-Service Procurement)
Our Take
SQL injection in a remote-enabled function module is inherently more exploitable than a local-only vulnerability. Procurement data manipulation has direct financial and audit implications. Include in your next planned window.
Vulnerability Detail
SQL injection vulnerability in a remote-enabled function module within the SAP S/4HANA Self-Service Procurement component. An authenticated attacker can inject SQL statements through unsanitised input, potentially accessing or modifying procurement data beyond their authorisation.
Patch Action
Apply SAP Note 3751691. Verify affected versions in the official SAP Note.
Patch Info