SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
| Software | From | Fixed in |
|---|---|---|
| sap / s/4_hana | 102 | 102.x |
| sap / s/4_hana | 103 | 103.x |
| sap / s/4_hana | 104 | 104.x |
| sap / s/4_hana | 105 | 105.x |
| sap / s/4_hana | 106 | 106.x |
| sap / s/4_hana | 107 | 107.x |
| sap / s/4_hana | 108 | 108.x |
| sap / s/4_hana | 109 | 109.x |