Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the legitimate user from accessing the records, causing low impact on application availability.
Metrics
Affected Vendors & Products
References
History
Tue, 12 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap S/4hana Condition Maintenance |
|
| Vendors & Products |
Sap Se
Sap Se sap S/4hana Condition Maintenance |
Tue, 12 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the legitimate user from accessing the records, causing low impact on application availability. | |
| Title | Missing Authorization check in SAP S/4HANA Condition Maintenance | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2026-05-12T02:21:18.130Z
Updated: 2026-05-12T13:15:10.607Z
Reserved: 2026-04-09T17:29:44.663Z
Link: CVE-2026-40133
Updated: 2026-05-12T13:15:06.394Z
Status : Awaiting Analysis
Published: 2026-05-12T03:16:12.177
Modified: 2026-05-12T14:19:41.400
Link: CVE-2026-40133
No data.