HarborGuard / CVE
Back to search
HIGHCVE-2026-24322Published Modified CNA sap

CVE-2026-24322: Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity or availability.

Metrics

CVSS v3.1
7.7
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • SAP_SE / SAP Solution Tools Plug-In (ST-PI)
    ST-PI 2008_1_700 · 2008_1_710 · 740 · 758
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N