3.8

CVE-2026-58245

Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt SAP Advanced Planning and Optimization (Model Mix Planning)
Default Statusunaffected
Version SCMAPO 713
Status affected
Version 714
Status affected
Version S4CORE 102
Status affected
Version 103
Status affected
Version 104
Status affected
Version S4COREOP 104
Status affected
Version 105
Status affected
Version 106
Status affected
Version 107
Status affected
Version 108
Status affected
Version 109
Status affected
Version SCM 700
Status affected
Version 701
Status affected
Version 702
Status affected
Version 712
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.068
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
SAP 3.8 1.2 2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3763028