CVE-2026-0488

CRITICAL WAF: Low
CVSS 9.9 Published: 2026-02-10
CWE-862

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

WAF Coverage Analysis

Missing Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
sapnetweaver_application_server_abap700
saps\/4hana102
saps\/4hana103
saps\/4hana104
saps\/4hana105
saps\/4hana106
saps\/4hana107
saps\/4hana108
saps\/4hana109
sapwebclient_ui_framework700

References

Back to CVE Database