CVE-2026-76971
- EPSS 0.15%
- Veröffentlicht 08.09.2026 01:17:55
- Zuletzt bearbeitet 08.09.2026 19:12:59
Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined ...
CVE-2026-58244
- EPSS 0.17%
- Veröffentlicht 11.08.2026 00:16:44
- Zuletzt bearbeitet 26.08.2026 19:00:14
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users....
CVE-2026-44765
- EPSS 0.28%
- Veröffentlicht 11.08.2026 00:12:05
- Zuletzt bearbeitet 26.08.2026 19:00:14
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploit...
CVE-2026-44764
- EPSS 0.24%
- Veröffentlicht 11.08.2026 00:11:53
- Zuletzt bearbeitet 26.08.2026 19:00:14
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these ...
CVE-2026-44763
- EPSS 0.28%
- Veröffentlicht 11.08.2026 00:11:42
- Zuletzt bearbeitet 26.08.2026 19:00:14
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attac...
CVE-2026-44758
- EPSS 0.51%
- Veröffentlicht 11.08.2026 00:11:19
- Zuletzt bearbeitet 26.08.2026 19:00:14
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow th...
- EPSS 50.91%
- Veröffentlicht 09.03.2021 15:15:14
- Zuletzt bearbeitet 05.05.2025 17:16:58
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashb...
CVE-2019-0267
- EPSS 0.72%
- Veröffentlicht 15.02.2019 18:29:02
- Zuletzt bearbeitet 21.11.2024 04:16:36
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external applicat...
- EPSS 0.97%
- Veröffentlicht 24.11.2015 20:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.