CVE-2024-44121
- EPSS 0.29%
- Veröffentlicht 10.09.2024 05:15:11
- Zuletzt bearbeitet 15.04.2026 00:35:42
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does ...
CVE-2024-4139
- EPSS 0.29%
- Veröffentlicht 14.05.2024 16:17:33
- Zuletzt bearbeitet 15.04.2026 00:35:42
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the int...
CVE-2024-4138
- EPSS 0.29%
- Veröffentlicht 14.05.2024 16:17:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other user...
CVE-2024-33002
- EPSS 0.33%
- Veröffentlicht 14.05.2024 16:17:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
CVE-2024-30217
- EPSS 0.32%
- Veröffentlicht 09.04.2024 01:15:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting...
CVE-2024-30216
- EPSS 0.32%
- Veröffentlicht 09.04.2024 01:15:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status a...
CVE-2023-42475
- EPSS 0.44%
- Veröffentlicht 10.10.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 08:22:37
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
CVE-2023-42473
- EPSS 0.27%
- Veröffentlicht 10.10.2023 02:15:10
- Zuletzt bearbeitet 21.11.2024 08:22:37
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application.
CVE-2023-40306
- EPSS 0.33%
- Veröffentlicht 08.09.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 08:19:12
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
CVE-2023-24524
- EPSS 0.52%
- Veröffentlicht 14.02.2023 04:15:12
- Zuletzt bearbeitet 21.11.2024 07:48:03
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability. ...