CVE-2025-43010
- EPSS 0.05%
- Veröffentlicht 13.05.2025 00:19:51
- Zuletzt bearbeitet 13.05.2025 19:35:18
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard p...
CVE-2025-43003
- EPSS 0.05%
- Veröffentlicht 13.05.2025 00:18:25
- Zuletzt bearbeitet 13.05.2025 19:35:18
SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout displaying this field. On performing this step the attacker could gain access to highly sensitive info...
CVE-2025-27429
- EPSS 0.1%
- Veröffentlicht 08.04.2025 07:13:37
- Zuletzt bearbeitet 08.04.2025 18:13:53
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerabilit...
CVE-2025-27436
- EPSS 0.07%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted ban...
CVE-2025-27433
- EPSS 0.07%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity,...
CVE-2025-26656
- EPSS 0.07%
- Veröffentlicht 11.03.2025 01:15:35
- Zuletzt bearbeitet 11.03.2025 01:15:35
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
CVE-2024-44121
- EPSS 0.11%
- Veröffentlicht 10.09.2024 05:15:11
- Zuletzt bearbeitet 10.09.2024 12:09:50
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does ...
CVE-2024-4139
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:17:33
- Zuletzt bearbeitet 21.11.2024 09:42:15
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the int...
CVE-2024-4138
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:17:32
- Zuletzt bearbeitet 21.11.2024 09:42:15
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other user...
CVE-2024-33002
- EPSS 0.18%
- Veröffentlicht 14.05.2024 16:17:13
- Zuletzt bearbeitet 21.11.2024 09:16:12
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.