CVE-2024-44121: SAP SE SAP s/4 Hana Statutory Reports

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not impact the integrity and availability of the application

Affected products

  • SAP SE SAP s/4 Hana Statutory Reports: version 900 only

Published 2024-09-10. Last modified 2026-06-17.