{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-0494",
        "assignerOrgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
        "state": "PUBLISHED",
        "assignerShortName": "sap",
        "dateReserved": "2025-12-09T22:06:36.684Z",
        "datePublished": "2026-01-13T01:13:14.370Z",
        "dateUpdated": "2026-01-13T16:19:32.833Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "SAP Fiori App (Intercompany Balance Reconciliation)",
                    "vendor": "SAP_SE",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "UIAPFI70 500"
                        },
                        {
                            "status": "affected",
                            "version": "600"
                        },
                        {
                            "status": "affected",
                            "version": "700"
                        },
                        {
                            "status": "affected",
                            "version": "800"
                        },
                        {
                            "status": "affected",
                            "version": "900"
                        },
                        {
                            "status": "affected",
                            "version": "901"
                        },
                        {
                            "status": "affected",
                            "version": "902"
                        },
                        {
                            "status": "affected",
                            "version": "UIS4H 109"
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<p>Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.</p>"
                        }
                    ],
                    "value": "Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "LOW",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "LOW",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-497",
                            "description": "CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere",
                            "lang": "eng",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
                "shortName": "sap",
                "dateUpdated": "2026-01-13T01:13:14.370Z"
            },
            "references": [
                {
                    "url": "https://me.sap.com/notes/3655227"
                },
                {
                    "url": "https://url.sap/sapsecuritypatchday"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)",
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-01-13T16:19:26.654230Z",
                                "id": "CVE-2026-0494",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-01-13T16:19:32.833Z"
                }
            }
        ]
    }
}