Executive brief
SAP Manufacturing Integration and Intelligence (MII) is a manufacturing execution system used by enterprises to manage production processes. A flaw in the application fails to properly check user permissions on certain functions, allowing a low-privileged employee to view account information and user details that should only be accessible to administrators. An attacker could exploit this to gather information about user accounts and use that knowledge to launch targeted attacks against other users.
Technical details
This is an authorization check bypass vulnerability in SAP MII where certain application functions do not properly validate user permissions before granting access to restricted data. The vulnerability requires the attacker to be an authenticated user with low-level privileges within the application. Through exploitation, an attacker can access user account information that should be restricted to privileged users only. No integrity or availability impact is expected; the issue is limited to unauthorized information disclosure (confidentiality). A patch is expected to be available via SAP Security Patch Day.
Affected products
- SAP Manufacturing Integration and Intelligence
Timeline
- 2026-08-11: disclosed