
- SAP patches critical S/4HANA flaw which allowed full system takeover
- Attackers can inject ABAP code and bypass authorization using RFC
- Some systems remain unpatched, and confirmed abuse has already occurred
S/4HANA, SAP’s Enterprise Resource Planning (ERP) software suite, was carrying a critical vulnerability which allowed threat actors to fully take over vulnerable endpoints.