First published: Tue Mar 11 2025(Updated: )
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Just In Time |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26655 is classified as a low severity vulnerability due to its limited impact on integrity.
CVE-2025-26655 allows for privilege escalation, which could compromise application integrity.
To fix CVE-2025-26655, ensure that proper authorization checks are implemented in the SAP Just In Time (JIT) system.
CVE-2025-26655 affects users of the SAP Just In Time (JIT) application.
CVE-2025-26655 is an authorization vulnerability that allows users to escalate privileges.