Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.
History

Tue, 03 Mar 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap s\/4hana Uiapfi70
Sap s\/4hana Uis4h
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:sap:s\/4hana_uiapfi70:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:900:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:901:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uiapfi70:902:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_uis4h:109:*:*:*:*:*:*:*
Vendors & Products Sap
Sap s\/4hana Uiapfi70
Sap s\/4hana Uis4h

Wed, 25 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Feb 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se s/4hana (manage Payment Media)
Vendors & Products Sap Se
Sap Se s/4hana (manage Payment Media)

Tue, 24 Feb 2026 05:45:00 +0000

Type Values Removed Values Added
Description Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.
Title Information Disclosure vulnerability in S/4HANA (Manage Payment Media)
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2026-02-24T05:23:52.911Z

Updated: 2026-02-24T16:44:18.533Z

Reserved: 2026-01-21T22:15:25.361Z

Link: CVE-2026-24314

cve-icon Vulnrichment

Updated: 2026-02-24T16:44:11.718Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T06:16:35.270

Modified: 2026-03-03T00:28:43.917

Link: CVE-2026-24314

cve-icon Redhat

No data.