SAP Service Parts Management Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in SAP Service Parts Management (SPM). The issue arises because the application fails to implement necessary authorization checks for authenticated users, allowing attackers to escalate privileges. This vulnerability has a low impact on the application's confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation within the application.

Remediation

Users are advised to review and implement the SAP Security Notes available in SAP for Me. Security fixes for SAP NetWeaver-based products are delivered with support packages. For details on the SAP Security Patch Day schedule and how to access SAP Security Notes, refer to the SAP Security Notes FAQ.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.