# CVE-2026-24319

## Summary

- **CVE ID:** CVE-2026-24319
- **Severity:** MEDIUM
- **CVSS Score:** 5.8 (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N)
- **CWE:** CWE-316
- **Published:** Feb 10, 2026
- **Last Modified:** Mar 12, 2026

## Description

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.

## Affected Products

- SAP_SE — SAP Business One (B1 Client Memory Dump Files) (B1_ON_HANA 10.0)
- SAP_SE — SAP Business One (B1 Client Memory Dump Files) (SAP-M-BO 10.0)

## References

- [CNA](https://me.sap.com/notes/3679346)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.09%
- **EPSS Percentile:** 0.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._