CVE-2025-26656

MEDIUM

SAP S/4HANA Manage Purchasing Info Records - Authenticated Privilege Escalation via OData Service

Title source: llm
STIX 2.1

Description

OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0008
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (4)
SAP_SE/S/4HANA (Manage Purchasing Info Records) 106
SAP_SE/S/4HANA (Manage Purchasing Info Records) 107
SAP_SE/S/4HANA (Manage Purchasing Info Records) 108
SAP_SE/S/4HANA (Manage Purchasing Info Records) S4CORE 105
Published Mar 11, 2025
Tracked Since Feb 18, 2026