216.73.217.22

CVE-2026-27684

· Published 10/03/2026 17:38 · Modified 11/03/2026 13:53

Labels: CVE-2026-27684 2026-03-10CVE-2026-27684CWE-89[email protected]

Essential information

Published
10/03/2026 17:38
Modified
11/03/2026 13:53
Author
Creator
CVSS
6.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L

CVSS metrics

Description

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL queries without proper validation or escaping. As a result, an attacker can manipulate the WHERE clause logic and potentially gain unauthorized access to or modify database information. This vulnerability has no impact on integrity and low impact on the confidentiality and availability of the application.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sap / netweaver cpe:2.3:a:sap:netweaver:*:*:*:*:*:*:*:*

References