Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 17 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Application Server Abap Sap s\/4hana Sap webclient Ui Framework |
|
| CPEs | cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:102:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:103:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:104:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:105:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:106:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:107:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:108:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4hana:109:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:700:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:701:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:730:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:731:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:746:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:747:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:748:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:800:*:*:*:*:*:*:* cpe:2.3:a:sap:webclient_ui_framework:801:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap netweaver Application Server Abap Sap s\/4hana Sap webclient Ui Framework |
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap Crm And Sap S/4hana (scripting Editor) |
|
| Vendors & Products |
Sap Se
Sap Se sap Crm And Sap S/4hana (scripting Editor) |
Tue, 10 Feb 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability. | |
| Title | Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-02-26T15:04:14.152Z
Reserved: 2025-12-09T22:06:31.935Z
Link: CVE-2026-0488
Updated: 2026-02-10T15:42:53.926Z
Status : Analyzed
Published: 2026-02-10T04:16:01.710
Modified: 2026-02-17T16:10:03.600
Link: CVE-2026-0488
No data.
OpenCVE Enrichment
Updated: 2026-04-17T21:15:27Z