Impact
The Material Master application does not enforce authorization checks for authenticated users when executing reports, exposing sensitive information. This missing access control flaw is classified as CWE‑862. The impact is limited to a low confidentiality loss; there is no reported effect on integrity or availability, but the disclosed data could still be valuable to an attacker.
Affected Systems
SAP SE Material Master Application is the affected product. Version information is not specified in the provided data, meaning all deployments may be vulnerable until a patch is released and applied.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and there is no EPSS data available to gauge exploitation probability. The CVE is not listed in the CISA KEV catalog, suggesting it is not widely exploited. The likely attack vector is an authenticated user triggering report generation, so threat actors would need valid credentials or stolen credentials to benefit. Because the vulnerability only discloses confidential data, the overall risk is moderate, but the issue should be addressed promptly.
OpenCVE Enrichment