SAP Financial Consolidation Session Termination Vulnerability Allowing Denial-of-Service

Vulnerability

A vulnerability in SAP Financial Consolidation allows authenticated attackers to temporarily disconnect other users by terminating their sessions, which can lead to a denial-of-service condition. This disruption prevents the affected users from accessing the application. However, the vulnerability does not compromise the application itself, resulting in a low impact on availability. Additionally, there is no effect on the confidentiality or integrity of the data.

Impact

Exploitation of this vulnerability causes a temporary denial-of-service condition by disconnecting users and preventing them from accessing the application.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where users can find the complete list of security notes and prioritize their implementation.

Added: May 12, 2026, 3:19 AM
Updated: May 12, 2026, 3:19 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
4.9
remediation
0.0
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.