Impact
SAP S/4HANA (Private Cloud) incorporates a third‑party component that is vulnerable to a Regular Expression Denial of Service (ReDoS). An attacker who does not need to be authenticated can supply specially crafted input that forces the component to perform excessive processing, draining system resources. If the vulnerability is successfully exploited the service can become unavailable, resulting in a high impact on availability while confidentiality and integrity remain unaffected.
Affected Systems
The affected product is SAP S/4HANA (Manage Supply Protection) running in a private‑cloud environment. The specific affected versions are not listed, but the vulnerability applies to any deployment that includes the third‑party component referenced in the advisory.
Risk and Exploitability
The CVSS score of 7.5 rates this vulnerability as high severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation in the wild. However, an unauthenticated attacker can reach the vulnerable functionality, and the complexity of exploitation is low based on the description. Consequently, the risk is significant and should be mitigated promptly.
OpenCVE Enrichment