Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Feb 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap advanced Planning And Optimization
|
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:sap:advanced_planning_and_optimization:713:*:*:*:*:*:*:* cpe:2.3:a:sap:advanced_planning_and_optimization:714:*:*:*:*:*:*:* cpe:2.3:a:sap:supply_chain_management:700:*:*:*:*:*:*:* cpe:2.3:a:sap:supply_chain_management:701:*:*:*:*:*:*:* cpe:2.3:a:sap:supply_chain_management:702:*:*:*:*:*:*:* cpe:2.3:a:sap:supply_chain_management:712:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap advanced Planning And Optimization
|
Tue, 10 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap supply Chain Management |
|
| Vendors & Products |
Sap
Sap supply Chain Management |
Tue, 10 Feb 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected. | |
| Title | Denial of service (DOS) in SAP Supply Chain Management | |
| Weaknesses | CWE-606 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-02-10T03:03:09.536Z
Reserved: 2026-01-14T18:26:17.297Z
Link: CVE-2026-23689
No data.
Status : Analyzed
Published: 2026-02-10T04:16:03.500
Modified: 2026-02-17T15:57:04.273
Link: CVE-2026-23689
No data.
OpenCVE Enrichment
Updated: 2026-02-10T15:37:18Z