Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34264

Опубликовано: 14 апр. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:sap:human_capital_management:s4hcmrxx_100:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:s4hcmrxx_101:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:s4hcmrxx_102:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_600:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_604:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_608:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana:-:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.00269
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 6.5
github
4 месяца назад

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость программного обеспечения управления ресурсами человеческого капитала в организации SAP Human Capital Management (HCM), связанная с несоответствием ответов на входящие запросы, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 19%
0.00269
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-204