← Back

CVE-2026-24314

nvd nist
Published: Feb 24, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: CNA (Secondary)

Description

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.

Affected (7)

2 products
S/4hana Uiapfi70
S/4hana Uis4h
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 600
Version 700
Version 800
Version 900
Version 901
Version 902
Version 109

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.