CVE-2025-26656
- EPSS 0.08%
- Veröffentlicht 11.03.2025 01:15:35
- Zuletzt bearbeitet 11.03.2025 01:15:35
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
CVE-2024-44121
- EPSS 0.15%
- Veröffentlicht 10.09.2024 05:15:11
- Zuletzt bearbeitet 10.09.2024 12:09:50
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does ...
CVE-2024-4139
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:17:33
- Zuletzt bearbeitet 21.11.2024 09:42:15
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the int...
CVE-2024-4138
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:17:32
- Zuletzt bearbeitet 21.11.2024 09:42:15
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other user...
CVE-2024-33002
- EPSS 0.18%
- Veröffentlicht 14.05.2024 16:17:13
- Zuletzt bearbeitet 21.11.2024 09:16:12
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
CVE-2024-30217
- EPSS 0.07%
- Veröffentlicht 09.04.2024 01:15:50
- Zuletzt bearbeitet 21.11.2024 09:11:28
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting...
CVE-2024-30216
- EPSS 0.09%
- Veröffentlicht 09.04.2024 01:15:50
- Zuletzt bearbeitet 21.11.2024 09:11:27
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status a...
CVE-2023-42475
- EPSS 0.2%
- Veröffentlicht 10.10.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 08:22:37
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
CVE-2023-42473
- EPSS 0.15%
- Veröffentlicht 10.10.2023 02:15:10
- Zuletzt bearbeitet 21.11.2024 08:22:37
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application.
CVE-2023-40306
- EPSS 0.1%
- Veröffentlicht 08.09.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 08:19:12
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.