CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-0498

CVSS 9.1v3.1pub. 2026-01-13upd. 2026-01-22

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

🤖 AI Analysis
How it works

An attacker with administrator privileges exploits a functional module exposed through the RFC (Remote Function Call) interface. The vulnerability lies in insufficient input data validation (CWE-94: Improper Control of Code Generation), which allows injection of arbitrary ABAP code or operating system commands. The mechanism bypasses required authorization controls, acting in practice as a backdoor. As a result, the attacker gains full control over the system, compromising its confidentiality, integrity and availability.

Impact

An attacker can achieve full compromise of the SAP S/4HANA system — execute arbitrary ABAP code or operating system commands, leading to loss of confidentiality, integrity and availability of data and the entire SAP environment.

Mitigation & patch

Apply patches available from the vendor according to references — SAP Security Note 3694242 (https://me.sap.com/notes/3694242) published as part of SAP Security Patch Day. It is also recommended to restrict access to the RFC interface only to trusted hosts and audit accounts with administrator privileges.

Who is affected

SAP S/4HANA in Private Cloud and On-Premise variants; specific versions indicated in vendor references (SAP Security Note 3694242).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Sap S\/4 Hana

    APP
    Sap
    102103104105106107108109
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2020-26832HIGH7.6same product

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_...

CVE-2020-6188HIGH8.8same product

VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617,...

CVE-2024-45282MEDIUM4.3same product

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be ...

CVE-2024-34691MEDIUM6.5same product

Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an au...

CVE-2023-41368LOW2.7same product

Usługa OData aplikacji S4 HANA (Manage checkbook apps) — w wersjach 102, 103, 104, 105, 106, 107 — pozwala ata...