Ad

CVE-2026-27684

MEDIUM CVSS 3.1: 6.4 EPSS 0.04%
Updated Mar 10, 2026
SAP
Parameter Value
CVSS 6.4 (MEDIUM)
Type CWE-89 (SQL Injection)
Vendor SAP
Public PoC No

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL queries without proper validation or escaping. As a result, an attacker can manipulate the WHERE clause logic and potentially gain unauthorized access to or modify database information.

This vulnerability has no impact on integrity and low impact on the confidentiality and availability of the application.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)