6.5

CVE-2026-34264

Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Human Capital Management Version s4hcmrxx_100
SAP ≫ Human Capital Management Version s4hcmrxx_101
SAP ≫ Human Capital Management Version s4hcmrxx_102
SAP ≫ Human Capital Management Version sap_hrrxx_600
SAP ≫ Human Capital Management Version sap_hrrxx_604
SAP ≫ Human Capital Management Version sap_hrrxx_608
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.182
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
SAP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-204 Observable Response Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

https://url.sap/sapsecuritypatchday
Permissions Required
https://me.sap.com/notes/3680767
Permissions Required