VDB

CVE-2026-44770

CVE-2026-44770 PUBLISHED CVSS 4.3 MEDIUM

Reported by sap · Published July 14, 2026

SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
SAP_SESAP S/4 HANA (Create Single Payment)S4CORE 102, 103, 104
SAP_SESAP S/4 HANA (Create Single Payment)S4CORE 102, 103, 104

Timeline

  • Jul 14, 2026 EPSS Score
  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Jul 14, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›