Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap Incentive And Commission Management |
|
| Vendors & Products |
Sap Se
Sap Se sap Incentive And Commission Management |
Tue, 12 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availability of the application. | |
| Title | Missing Authorization Check in SAP Incentive and Commission Management | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-05-12T13:11:34.915Z
Reserved: 2026-04-09T17:29:44.663Z
Link: CVE-2026-40134
Updated: 2026-05-12T13:11:32.049Z
Status : Awaiting Analysis
Published: 2026-05-12T03:16:12.307
Modified: 2026-05-12T14:19:41.400
Link: CVE-2026-40134
No data.
OpenCVE Enrichment
Updated: 2026-05-12T09:21:58Z