CVE-2026-0512
Cross-Site Scripting in SAP SRM SICF Handler Enables Data Manipulation
Publication date: 2026-04-14
Last updated on: 2026-04-14
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | supplier_relationship_management | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Cross-Site Scripting (XSS) issue found in the SAP Supplier Relationship Management system, specifically in the SICF Handler within the SRM Catalog. An attacker who is not authenticated can create a malicious URL. If a victim clicks on this URL, malicious code can execute within the victim's browser.
This execution of malicious content can allow the attacker to access and modify information within the application.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing an attacker to access and modify sensitive information within the SAP Supplier Relationship Management application. This affects the confidentiality and integrity of your data.
However, the availability of the application is not affected by this vulnerability.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability allows an unauthenticated attacker to execute malicious content in a victim's browser, potentially leading to unauthorized access and modification of information. Such impacts on confidentiality and integrity could pose risks to compliance with standards and regulations that require protection of sensitive data, such as GDPR and HIPAA.
However, the provided information does not explicitly detail the direct effects on compliance with these standards or any specific regulatory implications.