CVE-2025-27429
- EPSS 0.08%
- Veröffentlicht 08.04.2025 07:13:37
- Zuletzt bearbeitet 08.04.2025 18:13:53
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerabilit...
CVE-2025-27436
- EPSS 0.05%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted ban...
CVE-2025-27433
- EPSS 0.05%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity,...
CVE-2025-26656
- EPSS 0.05%
- Veröffentlicht 11.03.2025 01:15:35
- Zuletzt bearbeitet 11.03.2025 01:15:35
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
CVE-2024-44121
- EPSS 0.13%
- Veröffentlicht 10.09.2024 05:15:11
- Zuletzt bearbeitet 10.09.2024 12:09:50
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does ...
CVE-2024-4139
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:17:33
- Zuletzt bearbeitet 21.11.2024 09:42:15
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the int...
CVE-2024-4138
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:17:32
- Zuletzt bearbeitet 21.11.2024 09:42:15
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other user...
CVE-2024-33002
- EPSS 0.18%
- Veröffentlicht 14.05.2024 16:17:13
- Zuletzt bearbeitet 21.11.2024 09:16:12
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
CVE-2024-30217
- EPSS 0.09%
- Veröffentlicht 09.04.2024 01:15:50
- Zuletzt bearbeitet 21.11.2024 09:11:28
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting...
CVE-2024-30216
- EPSS 0.07%
- Veröffentlicht 09.04.2024 01:15:50
- Zuletzt bearbeitet 21.11.2024 09:11:27
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status a...