SAPCVE-2026-44769
SAP S/4HANA Project Management (PPM-PRO): SQL injection
Medium5.5CVE-2026-44769 · Published Jul 14, 2026
SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP S/4HANA Project Management (PPM-PRO) Product | <= SAP_APPL 600 | No fix yet |
| <= 602 | No fix yet | |
| <= 603 | No fix yet | |
| <= 604 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-89
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented... | Critical9.1 | No fix yet |
| Jul 14 | SAP @ui5/webcomponents-base: clickjacking | Medium6.1 | No fix yet |
| Jul 14 | SAP CRM (WebClient UI): attacker could inject | Medium4.1 | No fix yet |
| Jul 14 | SAP S/4 HANA (Create Single Payment): missing authorization | Medium4.3 | No fix yet |
| Jul 14 | SAP S/4HANA (Draft operation): privilege escalation | Medium4.3 | No fix yet |
| Jul 14 | SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization | High7.6 | No fix yet |