CVE-2026-0498
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Vendor
Product
CWE
Yayın Tarihi
2026-01-13 02:15:52
Güncelleme
2026-01-22 18:44:20
Source Identifier
cna@sap.com
KEV Date Added
-