CVE-2026-0503
Unknown Unknown - Not Provided
Authorization Bypass in SAP ECC and S/4HANA EHS Management

Publication date: 2026-01-13

Last updated on: 2026-01-13

Assigner: SAP SE

Description
Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or delete certain change pointer information within EHS objects in the application which might further affect the subsequent systems. This vulnerability leads to a low impact on confidentiality and integrity of the application with no affect on the availability.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-13
Last Modified
2026-01-13
Generated
2026-05-27
AI Q&A
2026-01-13
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
sap erp_central_component *
sap s_4hana *
sap ehs_management *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists due to a missing authorization check in SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management). An attacker can exploit this by extracting hardcoded clear-text credentials and bypassing the password authentication check through manipulation of user parameters. Successful exploitation allows the attacker to access, modify, or delete certain change pointer information within EHS objects in the application, potentially affecting subsequent systems.


How can this vulnerability impact me? :

The vulnerability can impact you by allowing an attacker to gain unauthorized access to certain data within the SAP EHS Management system. They can modify or delete change pointer information, which may affect downstream systems relying on this data. The impact is considered low on confidentiality and integrity, and there is no impact on availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart