Sceawere
Vulnerability Detail
CVE-2026-44764UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SAP MII Cost Servlet Authorization Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 4h ago
- Vendor
- SAP_SE
- Product
- SAP Manufacturing Integration and Intelligence
- Attack Type
- CWE-862: Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-08-11T01:17:21.053Z",
"pubdate": "2026-08-11T01:17:21.053Z",
"executiveSummary": "A Missing Authorization Check vulnerability has been identified in SAP Manufacturing Integration and Intelligence. The flaw exists within the Cost Servlet component, allowing unauthenticated remote threat actors to interact with backend operations by supplying specifically crafted parameter values within HTTP requests. Successful exploitation of this vulnerability grants unauthorized actors the ability to perform full CRUD operations—reading, creating, modifying, and deleting—on application-managed business data. While the scope of the impact is technically confined to the application layer rather than the underlying operating system, the compromise of critical business data leads to a tangible reduction in confidentiality, integrity, and availability. The attack vector requires network connectivity to the affected SAP Manufacturing Integration and Intelligence service, but does not necessitate prior authentication or specialized privileges, lowering the complexity barrier for potential adversaries. Organizations utilizing vulnerable versions of the software face significant risk regarding data integrity and business continuity due to the exposure of sensitive backend transactional processes.",
"technicalDetails": "The vulnerability is rooted in an insufficient access control implementation within the routing and permission validation logic of SAP Manufacturing Integration and Intelligence. Specifically, the Cost Servlet fails to properly enforce session validation or role-based access control checks prior to processing incoming HTTP requests directed at sensitive backend functional routines.\nThe attack flow initiates when an unauthenticated remote attacker crafts a specialized HTTP request containing targeted parameter values designed to interface with the Cost Servlet. Because the servlet lacks adequate authorization validation primitives, it processes the incoming payload and routes the execution flow directly to underlying backend operations that should otherwise be strictly restricted to authenticated and authorized administrative or operational personnel.\nThe vulnerable component is the Cost Servlet integrated within SAP Manufacturing Integration and Intelligence. The attack vector is network-based, exposing the endpoint to any entity capable of reaching the application's HTTP/HTTPS service ports. No prior authentication, user credentials, or specific privilege levels are required by the attacker to successfully transmit the malicious parameters and trigger the flaw.\nUpon successful processing of the crafted request by the application logic, the payload behavior enables unauthorized transactional execution against backend data structures. Post-exploitation impact encompasses the complete compromise of application-managed business data. The attacker can execute unauthorized read operations to harvest sensitive metrics, create fraudulent entries, modify existing operational configurations or financial data, and delete critical business records. This directly undermines the confidentiality, integrity, and availability posture of the affected SAP Manufacturing Integration and Intelligence deployment without necessarily triggering standard application-level authentication alerts."
}