Description
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.
Published: 2026-07-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a missing authorization check in SAP S/4 HANA’s Create Single Payment transaction, allowing an authenticated user to view entity set keys that should be protected. This flaw only affects the confidentiality of data, with no impact on integrity or availability. The vulnerability is identified as CWE‑862 and results in low‑impact information exposure.

Affected Systems

The vulnerability affects SAP S/4 HANA systems that expose the Create Single Payment functionality. No specific version numbers are listed in the CVE data, so the issue applies to all deployments that have not yet applied the appropriate SAP security patch.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, reflecting the limited confidentiality impact. The EPSS score is < 1%, indicating an extremely low probability of exploitation, and the vulnerability is not included in the CISA KEV catalog, suggesting no confirmed widespread exploitation. Exploitation requires an authenticated session in SAP S/4 HANA; an attacker can use the Create Single Payment transaction to read unauthorized data but cannot modify or disrupt the system. The risk is higher when sensitive data is handled and user roles are not tightly managed.

Generated by OpenCVE AI on July 31, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP Note 3713902 to correct the missing authorization check.
  • Enforce least‑privilege access by limiting the Create Single Payment transaction to users who truly need it, and remove unnecessary permissions for restricted roles.
  • Monitor and log usage of the Create Single Payment transaction and set up alerts for abnormal access patterns.

Generated by OpenCVE AI on July 31, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap S/4 Hana (create Single Payment)
Vendors & Products Sap Se
Sap Se sap S/4 Hana (create Single Payment)

Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.
Title Missing Authorization check in SAP S/4 HANA (Create Single Payment)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Sap Se Sap S/4 Hana (create Single Payment)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-07-14T12:53:18.747Z

Reserved: 2026-05-07T18:39:44.147Z

Link: CVE-2026-44770

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:00:06Z

Weaknesses