6.6

CVE-2026-0496

Medienbericht

Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges  to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
Produkt SAP Fiori App (Intercompany Balance Reconciliation)
Default Statusunaffected
Version UIAPFI70 500
Status affected
Version 600
Status affected
Version 700
Status affected
Version 800
Status affected
Version 900
Status affected
Version 901
Status affected
Version 902
Status affected
Version S4CORE 102
Status affected
Version 103
Status affected
Version 104
Status affected
Version 105
Status affected
Version 106
Status affected
Version 107
Status affected
Version 108
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.203
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@sap.com 6.6 2.3 3.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.