CVE 6.5 MEDIUM

Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA_CVE-2026-34264

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

Basic Information

ID CVE-2026-34264
Source sap
Published Apr 14, 2026 at 00:09

Affected Product

Vendor SAP_SE
Product SAP Human Capital Management for SAP S/4HANA
Version S4HCMRXX 100
Affected Versions SAP_SE SAP Human Capital Management for SAP S/4HANA S4HCMRXX 100
SAP_SE SAP Human Capital Management for SAP S/4HANA 101
SAP_SE SAP Human Capital Management for SAP S/4HANA 102
SAP_SE SAP Human Capital Management for SAP S/4HANA SAP_HRRXX 600
SAP_SE SAP Human Capital Management for SAP S/4HANA 604
SAP_SE SAP Human Capital Management for SAP S/4HANA 608

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.