3.8
CVE-2026-58245
- EPSS 0.17%
- Veröffentlicht 11.08.2026 00:16:55
- Zuletzt bearbeitet 26.08.2026 19:00:14
- Erkennungen
Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP Advanced Planning and Optimization (Model Mix Planning)
Default Statusunaffected
Version
SCMAPO 713
Status
affected
Version
714
Status
affected
Version
S4CORE 102
Status
affected
Version
103
Status
affected
Version
104
Status
affected
Version
S4COREOP 104
Status
affected
Version
105
Status
affected
Version
106
Status
affected
Version
107
Status
affected
Version
108
Status
affected
Version
109
Status
affected
Version
SCM 700
Status
affected
Version
701
Status
affected
Version
702
Status
affected
Version
712
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.068 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| SAP | 3.8 | 1.2 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3763028