VDB

CISA-2026-27686

CISA-2026-27686 PUBLISHED CVSS 5.9 MEDIUM

Reported by sap · Published March 10, 2026

Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.

Risk Scores

CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H

Affected Products

VendorProductVersions
SAP_SESAP Business Warehouse (Service API)DW4CORE 200, 300, 400
SAP_SESAP Business Warehouse (Service API)DW4CORE 200, 400, PI_BASIS 2006_1_700

Timeline

  • Mar 10, 2026 CVE Published
  • Mar 10, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›