MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2026-23688

CVSS 4.3v3.1pub. 2026-02-10upd. 2026-02-17

SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Sap S4core

    APP
    Sap
    102103104105106107
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-33701CRITICAL9.1PL ✓same product

SQL Injection w SAP DMIS / S/4HANA — eskalacja do konta Superuser

CVE-2024-39592HIGH7.7same product

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escal...

CVE-2018-2484HIGH8.8same product

SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.1...

CVE-2026-0505MEDIUM6.1same product

Aplikacje BSP pozwalają niezauthentyfikowanemu użytkownikowi na manipulowanie parametrami URL kontrolowanymi p...

CVE-2026-24323MEDIUM6.1same product

Aplikacje BSP pozwalają niezauwierzytelnionego użytkownika na wstrzyknięcie złośliwego kodu skryptu poprzez pa...