VDB
CISA-2026-27686
CISA-2026-27686
PUBLISHED
CVSS 5.9 MEDIUM
Reported by sap · Published March 10, 2026
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.
Risk Scores
CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP Business Warehouse (Service API) | DW4CORE 200, 300, 400 |
| SAP_SE | SAP Business Warehouse (Service API) | DW4CORE 200, 400, PI_BASIS 2006_1_700 |
Timeline
- Mar 10, 2026 CVE Published
- Mar 10, 2026 CVE Updated