- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:17:40
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and do...
CVE-2026-24322
- EPSS 0.04%
- Veröffentlicht 10.02.2026 03:04:01
- Zuletzt bearbeitet 17.02.2026 15:23:50
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality an...
CVE-2026-23681
- EPSS 0.03%
- Veröffentlicht 10.02.2026 03:02:03
- Zuletzt bearbeitet 17.02.2026 16:04:47
Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system infor...
CVE-2026-0486
- EPSS 0.03%
- Veröffentlicht 10.02.2026 03:00:59
- Zuletzt bearbeitet 17.02.2026 16:11:29
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are ...