Description
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.
Published: 2026-08-11
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in the SAP Manufacturing Integration and Intelligence Cost Servlet. An unauthenticated attacker can send specially crafted requests that, if accepted by the application, allow direct access to backend operations. This enables the attacker to read, create, modify, or delete business data managed by the application, thereby compromising the confidentiality, integrity, and limited availability of that data.

Affected Systems

SAP Manufacturing Integration and Intelligence is the only product identified as affected. No specific version range is provided, so all installations of this product are potentially impacted until a remediation is applied.

Risk and Exploitability

The CVSS score of 7.3 denotes moderate to high severity. No EPSS score is available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. The likely attack path is via HTTP requests to the Cost Servlet endpoint, requiring network connectivity to the affected system and crafted parameters. Successful exploitation results in direct manipulation of business data, posing a significant risk to the confidentiality and integrity of that data.

Generated by OpenCVE AI on August 11, 2026 at 01:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch documented in SAP Note 3758910 as soon as it becomes available.
  • Restrict network access to the Cost Servlet or its underlying services to authorized hosts.
  • Review and enforce least‑privilege permissions on backend operations to ensure that only authenticated users can invoke them.

Generated by OpenCVE AI on August 11, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.
Title Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:11:53.124Z

Reserved: 2026-05-07T18:39:44.146Z

Link: CVE-2026-44764

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses