SAP S/4HANA Condition Maintenance Missing Authorization Check Vulnerability

Vulnerability

A vulnerability exists in SAP S/4HANA Condition Maintenance due to a missing authorization check. This flaw allows authenticated attackers to gain unauthorized access to view and modify condition table records. The vulnerability has a low impact on data confidentiality and integrity, and it may also disrupt access for legitimate users, causing a low impact on application availability.

Impact

Exploitation of this vulnerability could lead to unauthorized access and modification of condition table records, with a low impact on data confidentiality and integrity. Additionally, the vulnerability may cause availability issues for legitimate users by disrupting their access to the records.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where users can find a complete list of security updates and patches. It is recommended to implement these corrections as a priority.

Added: May 12, 2026, 3:23 AM
Updated: May 12, 2026, 3:23 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.9
exploitability
4.9
remediation
0.0
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.