CVE-2026-58245
3.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Summary
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | SCMAPO 713 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 714 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | S4CORE 102 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 103 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 104 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | S4COREOP 104 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 105 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 106 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 107 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 108 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 109 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | SCM 700 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 701 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 702 | affected |
| SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | 712 | affected |
Weaknesses
- CWE-798: CWE-798: Use of Hard-coded Credentials
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.