Executive brief
SAP Manufacturing Integration and Intelligence is an enterprise system used to manage manufacturing operations and supply chain intelligence. A server-side request forgery vulnerability allows attackers to make the application initiate arbitrary outbound requests, which could be chained with XML/XSL processing to execute scripts and compromise the confidentiality, integrity, or availability of the application.
Technical details
This is a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence that allows an attacker to cause the server to initiate arbitrary outbound requests. The vulnerability can be combined with XML/XSL processing attacks to enable script execution. The attack is network-reachable and does not require authentication based on the reported impact scope. Successful exploitation results in low impact to confidentiality, integrity, and availability. A patch is available via SAP Security Note 3786489, published on the SAP Security Patch Day scheduled for September 8, 2026.
Affected products
- SAP Manufacturing Integration and Intelligence
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: SAP Security Note 3786489