VYPR

MII

by SAP

CVEs (2)

  • CVE-2021-21480HigMar 9, 2021
    risk 0.61cvss 8.8epss 0.51

    SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users…

  • CVE-2026-58244MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation…