6.6
CVE-2026-0496
- EPSS 0.05%
- Veröffentlicht 13.01.2026 01:13:28
- Zuletzt bearbeitet 13.01.2026 14:03:18
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP Fiori App (Intercompany Balance Reconciliation)
Default Statusunaffected
Version
UIAPFI70 500
Status
affected
Version
600
Status
affected
Version
700
Status
affected
Version
800
Status
affected
Version
900
Status
affected
Version
901
Status
affected
Version
902
Status
affected
Version
S4CORE 102
Status
affected
Version
103
Status
affected
Version
104
Status
affected
Version
105
Status
affected
Version
106
Status
affected
Version
107
Status
affected
Version
108
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.135 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 6.6 | 2.3 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.