Impact
The vulnerability stems from a missing authorization check that allows an unauthenticated remote attacker to invoke scheduling‑related functions without credentials. The attacker can read, create, modify or delete scheduling data, resulting in unauthorized data access and potential integrity loss. The overall impact on confidentiality, integrity and availability is low, but the lack of authentication permits exploitation without user interaction.
Affected Systems
SAP Manufacturing Integration and Intelligence from SAP SE is affected. Specific version information was not disclosed; therefore, all currently deployed releases that have not yet applied the vendor’s patch are potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.3 denotes high severity. EPSS is not available, so the exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw permits remote unauthenticated access, the attack vector is likely network‑based, and an attacker can exploit it without additional credentials. The risk is moderate to high for environments that expose the scheduling API.
OpenCVE Enrichment