Critical SAP Alert: S/4HANA SQL Injection & Wily RCE Threaten Financial Data
ID: 5e7627fb-0996-5f3d-b18d-19a89aede226
STIX ID: report--5e7627fb-0996-5f3d-b18d-19a89aede226
Feed Name: securityonline.info
Threat Score
SAP issued 17 security notes on 2026-01-13 addressing multiple critical and high-severity flaws—notably CVE-2026-0501 (SQL injection, CVSS 9.9) in S/4HANA and CVE-2026-0500 (unauthenticated RCE, CVSS 9.6) in Wily Introscope—that can enable data exfiltration, arbitrary code execution, and full system compromise; organizations are strongly urged to apply the patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
