VYPR

Manufacturing Integration And Intelligence

by SAP

CVEs (9)

  • CVE-2021-21480HigMar 9, 2021
    risk 0.61cvss 8.8epss 0.51

    SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users…

  • CVE-2026-44758CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute…

  • CVE-2019-0267HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.

  • CVE-2026-44763HigAug 11, 2026
    risk 0.49cvss 7.6epss 0.00

    SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and…

  • CVE-2026-44765HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the…

  • CVE-2026-44764HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to…

  • CVE-2016-4016MedApr 14, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) 15 allows remote attackers to inject arbitrary web script or HTML via the title parameter to webdynpro/resources/sap.com/xapps~xmii~ui~admin~navigation/NavigationAp…

  • CVE-2026-58244MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation…

  • CVE-2015-8329Nov 24, 2015
    risk 0.00cvss epss 0.01

    SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.