CVE-2026-24311 PUBLISHED

Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0

Assigner: sap
Reserved: 21.01.2026 Published: 10.03.2026 Updated: 10.03.2026

The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow modifications to occur without validation. Such changes could affect system behaviour during startup, resulting in a high impact on the application's confidentiality and integrity, with a low impact on availability.

Metrics

CVSS Vector: CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
CVSS Score: 5.6

Product Status

Vendor SAP_SE
Product SAP Customer Checkout 2.0
Versions Default: unaffected
  • Version SAP_CUSTOMER_CHECKOUT 2.0 is affected

References

Problem Types