« Volver al listado

CVE-2026-34264

Estado: AnalizadaMedia (6.5)—

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-34264",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-34264",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-14T12:53:03.744277Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "SAP Human Capital Management for SAP S/4HANA",
          "versions": [
            {
              "status": "affected",
              "version": "S4HCMRXX 100"
            },
            {
              "status": "affected",
              "version": "101"
            },
            {
              "status": "affected",
              "version": "102"
            },
            {
              "status": "affected",
              "version": "SAP_HRRXX 600"
            },
            {
              "status": "affected",
              "version": "604"
            },
            {
              "status": "affected",
              "version": "608"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-14T01:16:04.200",
  "references": [
    {
      "url": "https://me.sap.com/notes/3680767",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://url.sap/sapsecuritypatchday",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-204"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected."
    }
  ],
  "lastModified": "2026-06-17T10:38:44.760",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:human_capital_management:s4hcmrxx_100:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5384DC3A-9770-407E-89F1-9FC134B5CF50"
            },
            {
              "criteria": "cpe:2.3:a:sap:human_capital_management:s4hcmrxx_101:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC80DB20-E930-410F-9972-CA4CF94CA9B5"
            },
            {
              "criteria": "cpe:2.3:a:sap:human_capital_management:s4hcmrxx_102:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "993CDDD4-73D5-47F5-8017-A47B151F6CD0"
            },
            {
              "criteria": "cpe:2.3:a:sap:human_capital_management:sap_hrrxx_600:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABD7D918-79F2-44BB-94A4-8950DAF2B4EB"
            },
            {
              "criteria": "cpe:2.3:a:sap:human_capital_management:sap_hrrxx_604:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22796CDB-3AAA-4323-8A5B-69C61CC2EF46"
            },
            {
              "criteria": "cpe:2.3:a:sap:human_capital_management:sap_hrrxx_608:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3321A186-7B46-42C7-B4B6-FAB96608BBF5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:s\\/4hana:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "61225714-D573-435F-9423-7AE6A8ED59BC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}