Impact
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hard‑coded credential in its source code that is used for authorizing certain functions. The credential can be used by anyone with privileged access to the code to bypass the application’s authorization checks and remove planning restrictions. Because the vulnerability involves only a small hard‑coded token, the potential damage is limited to confidentiality and integrity of planning data; availability remains unaffected. This weakness corresponds to CWE‑798, hard‑coded authentication non‑standard.
Affected Systems
The affected product is SAP Advanced Planning and Optimization (Model Mix Planning). No specific version ranges are listed in the advisory, so any deployment of this SAP module that has not been updated to remove the hard‑coded credential is potentially vulnerable.
Risk and Exploitability
The calculated CVSS score of 3.8 indicates low overall severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability can be exploited only by an attacker who has the ability to read the source code or diagnose the application; it does not provide network‑based remote execution. It is therefore likely limited to internal threat actors with elevated privileges.
OpenCVE Enrichment