CVE-2026-24322: Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity or availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24322?
CVE-2026-24322 has a high severity rating due to the potential for sensitive information disclosure.
How do I fix CVE-2026-24322?
To fix CVE-2026-24322, ensure that the necessary authorization checks are implemented in the affected function module.
What are the potential impacts of CVE-2026-24322?
CVE-2026-24322 can lead to unauthorized access to sensitive user information, impacting data confidentiality.
Which software is affected by CVE-2026-24322?
CVE-2026-24322 affects the SAP Solution Tools Plug-In (ST-PI) software.
Is there a patch available for CVE-2026-24322?
Yes, SAP typically offers patches for vulnerabilities like CVE-2026-24322, which should be applied to mitigate the risk.