CVE-2026-0488
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
Vendor
Product
CWE
Yayın Tarihi
2026-02-10 04:16:01
Güncelleme
2026-02-17 16:10:03
Source Identifier
cna@sap.com
KEV Date Added
-