SAP Manufacturing Integration Intelligence
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in SAP Manufacturing Integration Intelligence.
By the Year
In 2026 there have been 5 vulnerabilities in SAP Manufacturing Integration Intelligence with an average score of 7.1 out of ten. Manufacturing Integration Intelligence did not have any published security vulnerabilities last year. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 5 | 7.12 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 1 | 8.80 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 8.80 |
It may take a day or so for new Manufacturing Integration Intelligence vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent SAP Manufacturing Integration Intelligence Security Vulnerabilities
SAP MII Auth Bypass: Low-Privilege Info Disclosure
CVE-2026-58244
4.3 - Medium
- August 11, 2026
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users account information in the application, which could be leveraged to facilitate further attacks against the identified user accounts. This vulnerability results in low impact on confidentiality of the data, with no impact on the integrity and availability
AuthZ
SAP MII Missing Auth Check for Scheduling APIs
CVE-2026-44765
7.3 - High
- August 11, 2026
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability.
AuthZ
SAP MII Cost Servlet Missing Auth Enables Data Modification
CVE-2026-44764
7.3 - High
- August 11, 2026
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.
AuthZ
SAP MIUI Path Traversal to Write Files Outside Intended Directory
CVE-2026-44763
7.6 - High
- August 11, 2026
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attackers control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.
Directory traversal
SAP MII Arbitrary OS Command via Unvalidated Input (CWE-20)
CVE-2026-44758
9.1 - Critical
- August 11, 2026
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.
Code Injection
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment)
CVE-2021-21480
8.8 - High
- March 09, 2021
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users having at least SAP_XMII Developer role, malicious content in the dashboard gets executed, leading to remote code execution in the server, which allows privilege escalation. The malicious JSP code can contain certain OS commands, through which an attacker can read sensitive files in the server, modify files or even delete contents in the server thus compromising the confidentiality, integrity and availability of the server hosting the SAP MII application. Also, an attacker authenticated as a developer can use the application to upload and execute a file which will permit them to execute operating systems commands completely compromising the server hosting the application.
Code Injection
SAP Manufacturing Integration and Intelligence
CVE-2019-0267
8.8 - High
- February 15, 2019
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.
Session Riding
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for SAP Manufacturing Integration Intelligence or by SAP? Click the Watch button to subscribe.