5.1
CVE-2026-0495
- EPSS 0.03%
- Veröffentlicht 13.01.2026 01:13:20
- Zuletzt bearbeitet 13.01.2026 14:03:18
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP Fiori App (Intercompany Balance Reconciliation)
Default Statusunaffected
Version
UIAPFI70 500
Status
affected
Version
600
Status
affected
Version
700
Status
affected
Version
800
Status
affected
Version
900
Status
affected
Version
901
Status
affected
Version
902
Status
affected
Version
S4CORE 102
Status
affected
Version
103
Status
affected
Version
104
Status
affected
Version
105
Status
affected
Version
106
Status
affected
Version
107
Status
affected
Version
108
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 5.1 | 1 | 3.7 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
|
CWE-15 External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.