Impact
SAP Manufacturing Integration and Intelligence (MII) lacks an authorization check on specific application functions, enabling a low‑privileged authenticated attacker to read user account information that should be restricted. The information exposed has a small impact on confidentiality, with no effect on integrity or availability, but could be used to facilitate further attacks against the exposed user accounts.
Affected Systems
The vulnerability affects SAP Manufacturing Integration and Intelligence (SAP MII). Version details are not provided in the advisory; all installations of SAP MII should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 4.3 places this issue in the Medium range, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an authenticated attacker with low privileges, the attack vector is likely an internal or remote authenticated session where the attacker can invoke the unprotected function.
OpenCVE Enrichment