CVE-2026-24314

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.
References
Link Resource
https://me.sap.com/notes/3646297 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:s\/4hana_uiapfi70:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:900:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:901:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:902:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uis4h:109:*:*:*:*:*:*:*

History

03 Mar 2026, 00:28

Type Values Removed Values Added
CWE NVD-CWE-noinfo
Summary
  • (es) Bajo ciertas condiciones, SAP S/4HANA (Gestionar Medios de Pago) permite a un atacante autenticado acceder a información que de otro modo estaría restringida. Esto podría causar un impacto bajo en la confidencialidad de la aplicación, mientras que la integridad y la disponibilidad no se ven impactadas.
CPE cpe:2.3:a:sap:s\/4hana_uiapfi70:900:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:902:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:901:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uis4h:109:*:*:*:*:*:*:*
References () https://me.sap.com/notes/3646297 - () https://me.sap.com/notes/3646297 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
First Time Sap s\/4hana Uis4h
Sap
Sap s\/4hana Uiapfi70

24 Feb 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 06:16

Updated : 2026-03-03 00:28


NVD link : CVE-2026-24314

Mitre link : CVE-2026-24314

CVE.ORG link : CVE-2026-24314


JSON object : View

Products Affected

sap

  • s\/4hana_uiapfi70
  • s\/4hana_uis4h
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

NVD-CWE-noinfo