Количество 3
Количество 3
CVE-2026-0498
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
GHSA-4p53-w5pc-f48w
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
BDU:2026-00341
Уязвимость интерфейса Remote Function Call (RFC) программной платформы SAP S/4HANA, позволяющая нарушителю обойти ограничения безопасности, выполнить произвольный код и получить полный контроль над системой
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-0498 SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system. | CVSS3: 9.1 | 0% Низкий | 27 дней назад | |
GHSA-4p53-w5pc-f48w SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system. | CVSS3: 9.1 | 0% Низкий | 27 дней назад | |
BDU:2026-00341 Уязвимость интерфейса Remote Function Call (RFC) программной платформы SAP S/4HANA, позволяющая нарушителю обойти ограничения безопасности, выполнить произвольный код и получить полный контроль над системой | CVSS3: 9.1 | 0% Низкий | 27 дней назад |
Уязвимостей на страницу