CVE 4.3 MEDIUM

Missing Authorization check in Material Master Application_CVE-2026-27672

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

The Material Master application does not enforce authorization checks for authenticated users when executing reports, resulting in the disclosure of sensitive information. This vulnerability has a low impact on confidentiality and does not affect integrity and availability of the system.

Basic Information

ID CVE-2026-27672
Source sap
Published Apr 14, 2026 at 00:06

Affected Product

Vendor SAP_SE
Product Material Master Application
Version S4CORE 102
Affected Versions SAP_SE Material Master Application S4CORE 102
SAP_SE Material Master Application 103
SAP_SE Material Master Application 104
SAP_SE Material Master Application 105
SAP_SE Material Master Application 106
SAP_SE Material Master Application 107
SAP_SE Material Master Application 108
SAP_SE Material Master Application 109
SAP_SE Material Master Application SCM_BASIS 700
SAP_SE Material Master Application SCM_BASIS 701
SAP_SE Material Master Application SCM_BASIS 702
SAP_SE Material Master Application SCM_BASIS 712
SAP_SE Material Master Application SCM_BASIS 713
SAP_SE Material Master Application SCM_BASIS 714

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.