An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Netweaver_application_server_abap | Sap | 700 (including) | 700 (including) |
| S/4hana | Sap | 102 (including) | 102 (including) |
| S/4hana | Sap | 103 (including) | 103 (including) |
| S/4hana | Sap | 104 (including) | 104 (including) |
| S/4hana | Sap | 105 (including) | 105 (including) |
| S/4hana | Sap | 106 (including) | 106 (including) |
| S/4hana | Sap | 107 (including) | 107 (including) |
| S/4hana | Sap | 108 (including) | 108 (including) |
| S/4hana | Sap | 109 (including) | 109 (including) |
| Webclient_ui_framework | Sap | 700 (including) | 700 (including) |
| Webclient_ui_framework | Sap | 701 (including) | 701 (including) |
| Webclient_ui_framework | Sap | 730 (including) | 730 (including) |
| Webclient_ui_framework | Sap | 731 (including) | 731 (including) |
| Webclient_ui_framework | Sap | 746 (including) | 746 (including) |
| Webclient_ui_framework | Sap | 747 (including) | 747 (including) |
| Webclient_ui_framework | Sap | 748 (including) | 748 (including) |
| Webclient_ui_framework | Sap | 800 (including) | 800 (including) |
| Webclient_ui_framework | Sap | 801 (including) | 801 (including) |