SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity. | |
| Title | Denial of Service (DoS) in SAP S/4HANA (Manage Supply Protection) | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-08-25T09:52:18.316Z
Reserved: 2026-07-27T17:33:40.733Z
Link: CVE-2026-66766
Updated: 2026-08-25T09:52:13.629Z
Status : Received
Published: 2026-08-25T01:16:37.230
Modified: 2026-08-25T10:18:12.987
Link: CVE-2026-66766
No data.
OpenCVE Enrichment
Updated: 2026-08-25T02:30:03Z