CVE-2026-0501

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Debido a una validación de entrada insuficiente en SAP S/4HANA Private Cloud y On-Premise (Financials General Ledger), un usuario autenticado podría ejecutar consultas SQL manipuladas para leer, modificar y eliminar datos de la base de datos de backend. Esto conlleva un alto impacto en la confidencialidad, integridad y disponibilidad de la aplicación.

13 Jan 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 02:15

Updated : 2026-06-17 10:10


NVD link : CVE-2026-0501

Mitre link : CVE-2026-0501

CVE.ORG link : CVE-2026-0501


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')