๐Ÿ” CVE Alert

CVE-2026-27689

HIGH 7.7

Denial of service (DOS) in SAP Supply Chain Management

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

Vendor sap_se
Product sap supply chain management
Published Mar 10, 2026
Last Updated Mar 10, 2026
Stay Ahead of the Next One

Get instant alerts for sap_se sap supply chain management

Be the first to know when new high vulnerabilities affecting sap_se sap supply chain management are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

SAP_SE / SAP Supply Chain Management
SCMAPO 713 714 S4CORE 102 103 104 S4COREOP 105 106 107 108 109 SCM 700 701 702 712

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
me.sap.com: https://me.sap.com/notes/3719502 url.sap: https://url.sap/sapsecuritypatchday