Impact
The vulnerability is a missing authorization check in the SAP Manufacturing Integration and Intelligence Cost Servlet. An unauthenticated attacker can send specially crafted requests that, if accepted by the application, allow direct access to backend operations. This enables the attacker to read, create, modify, or delete business data managed by the application, thereby compromising the confidentiality, integrity, and limited availability of that data.
Affected Systems
SAP Manufacturing Integration and Intelligence is the only product identified as affected. No specific version range is provided, so all installations of this product are potentially impacted until a remediation is applied.
Risk and Exploitability
The CVSS score of 7.3 denotes moderate to high severity. No EPSS score is available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. The likely attack path is via HTTP requests to the Cost Servlet endpoint, requiring network connectivity to the affected system and crafted parameters. Successful exploitation results in direct manipulation of business data, posing a significant risk to the confidentiality and integrity of that data.
OpenCVE Enrichment