SQL Injection Vulnerability in SAP Social Intelligence by SAP
CVE-2026-66770
6.3MEDIUM
What is CVE-2026-66770?
An SQL Injection vulnerability has been identified in SAP Social Intelligence, allowing authenticated attackers to inject SQL Data Definition Language (DDL) commands directly into the underlying database. This exploitation enables attackers to make unauthorized alterations to the database structure, posing a risk to the system’s overall integrity and availability. Proper mitigation and security updates are essential to protect against such vulnerabilities.
Affected Version(s)
SAP Social Intelligence S4FND 102
SAP Social Intelligence 103
SAP Social Intelligence 104