5
CVE-2026-24313
- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:17:40
- Zuletzt bearbeitet 11.03.2026 13:53:47
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or availability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP Solution Tools Plug-In (ST-PI)
Default Statusunaffected
Version
ST-PI 2008_1_700
Status
affected
Version
2008_1_710
Status
affected
Version
740
Status
affected
Version
758
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.076 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.