CVE Explorer
CVE-2026-0503
Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or delete certain change pointer information within EHS objects in the application which might further affect the subsequent systems. This vulnerability leads to a low impact on confide
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)","vendor":"SAP_SE","versions":[{"status":"affected","version":"SAP_APPL 618"},{"status":"affected","version":"S4CORE 102"},{"status":"affected","version":"103"},{"status":"affected","version":"104"},{"status":"affected","version":"105"},{"status":"affected","version":"106"},{"status":"affected","version":"107"},{"status":"affected","version":"108"},{"status":"affected","version":"109"},{"status":"affected","version":"EA-APPL 605"},{"status":"affected","version":"606"},{"status":"affected","v…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:84f30f030360837c1e6af34ebdcbe59629fc2eb1c7e9cc1958c6cd69e79995cd · sha256:f751970fdc173ac9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:84f30f030360837c1e6af34ebdcbe59629fc2eb1c7e9cc1958c6cd69e79995cd · sha256:f751970fdc173ac9… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"eng","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:84f30f030360837c1e6af34ebdcbe59629fc2eb1c7e9cc1958c6cd69e79995cd · sha256:f751970fdc173ac9… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://me.sap.com/notes/3681523"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:84f30f030360837c1e6af34ebdcbe59629fc2eb1c7e9cc1958c6cd69e79995cd · sha256:f751970fdc173ac9… · /containers/cna/references/0
{"url":"https://url.sap/sapsecuritypatchday"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:84f30f030360837c1e6af34ebdcbe59629fc2eb1c7e9cc1958c6cd69e79995cd · sha256:f751970fdc173ac9… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.