Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27684

Опубликовано: 10 мар. 2026
Источник: nvd
CVSS3: 6.4
EPSS Низкий

Описание

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL queries without proper validation or escaping. As a result, an attacker can manipulate the WHERE clause logic and potentially gain unauthorized access to or modify database information. This vulnerability has no impact on integrity and low impact on the confidentiality and availability of the application.

EPSS

Процентиль: 19%
0.00267
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.4
github
6 месяцев назад

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL queries without proper validation or escaping. As a result, an attacker can manipulate the WHERE clause logic and potentially gain unauthorized access to or modify database information. This vulnerability has no impact on integrity and low impact on the confidentiality and availability of the application.

CVSS3: 6.4
fstec
6 месяцев назад

Уязвимость программной интеграционной платформы SAP NetWeaver, связанная с непринятием мер по защите структуры SQL-запроса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 19%
0.00267
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-89