Executive brief
SAP Manufacturing Integration and Intelligence is a manufacturing planning and execution system used to manage production scheduling and operations. An unauthenticated attacker could bypass authorization checks to access scheduling data, potentially retrieving, modifying, or deleting critical production information without proper access controls. This could disrupt manufacturing operations, expose sensitive scheduling data, and allow unauthorized changes to production plans.
Technical details
This vulnerability is a missing authorization check (CWE-862) in the scheduling-related functionality of SAP Manufacturing Integration and Intelligence. The application fails to validate authorization before allowing access to scheduling functions, permitting unauthenticated remote attackers to retrieve, create, modify, or delete scheduling data. No special privileges, authentication, or user interaction is required to exploit this vulnerability—an attacker on the network can directly access the affected functions. The vulnerability impacts confidentiality, integrity, and availability of scheduling data. A patch has been released by SAP and is available through their standard security patching process.
Affected products
- SAP Manufacturing Integration and Intelligence
Timeline
- 2026-08-11: disclosed