CVE-2025-42987
- EPSS 0.04%
- Veröffentlicht 10.06.2025 00:11:45
- Zuletzt bearbeitet 12.06.2025 16:06:39
SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, ...
CVE-2025-42984
- EPSS 0.05%
- Veröffentlicht 10.06.2025 00:11:29
- Zuletzt bearbeitet 12.06.2025 16:06:39
SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function import on the entity making it inaccessible for unrestricted user. This has lo...
CVE-2025-43010
- EPSS 0.07%
- Veröffentlicht 13.05.2025 00:19:51
- Zuletzt bearbeitet 13.05.2025 19:35:18
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard p...
CVE-2025-43003
- EPSS 0.06%
- Veröffentlicht 13.05.2025 00:18:25
- Zuletzt bearbeitet 13.05.2025 19:35:18
SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout displaying this field. On performing this step the attacker could gain access to highly sensitive info...
CVE-2025-27429
- EPSS 0.39%
- Veröffentlicht 08.04.2025 07:13:37
- Zuletzt bearbeitet 08.04.2025 18:13:53
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerabilit...
CVE-2025-27436
- EPSS 0.08%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted ban...
CVE-2025-27433
- EPSS 0.08%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity,...
CVE-2025-26656
- EPSS 0.08%
- Veröffentlicht 11.03.2025 01:15:35
- Zuletzt bearbeitet 11.03.2025 01:15:35
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
CVE-2024-44121
- EPSS 0.15%
- Veröffentlicht 10.09.2024 05:15:11
- Zuletzt bearbeitet 10.09.2024 12:09:50
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does ...
CVE-2024-4139
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:17:33
- Zuletzt bearbeitet 21.11.2024 09:42:15
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the int...