Skip to content
SAPCVE-2026-44769

SAP S/4HANA Project Management (PPM-PRO): SQL injection

Medium5.5CVE-2026-44769 · Published Jul 14, 2026

SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP S/4HANA Project Management (PPM-PRO)
Product
<= SAP_APPL 600No fix yet
<= 602No fix yet
<= 603No fix yet
<= 604No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-89

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...
Critical9.1Jul 14
SAP @ui5/webcomponents-base: clickjacking
Medium6.1Jul 14
SAP CRM (WebClient UI): attacker could inject
Medium4.1Jul 14
SAP S/4 HANA (Create Single Payment): missing authorization
Medium4.3Jul 14
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3Jul 14
SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization
High7.6Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.