SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the system, leading to SQL Injection.
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222