4.9
CVE-2026-27673
- EPSS 0.04%
- Veröffentlicht 14.04.2026 00:06:38
- Zuletzt bearbeitet 17.04.2026 15:18:16
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise)
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP S/4HANA (Private Cloud and On-Premise)
Default Statusunaffected
Version
S4CORE 105
Status
affected
Version
106
Status
affected
Version
107
Status
affected
Version
108
Status
affected
Version
109
Status
affected
Version
FI-CA 606
Status
affected
Version
616
Status
affected
Version
617
Status
affected
Version
618
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.123 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 4.9 | 1.8 | 2.7 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.