Access Control Vulnerability in SAP S/4HANA for Bank Statement Management
CVE-2025-27436
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 March 2025
What is CVE-2025-27436?
The Manage Bank Statements feature in SAP S/4HANA has been identified to lack essential access control checks for authenticated users. This oversight allows attackers to potentially delete attachments linked to submitted bank statements, which undermines the integrity of the bank statements without affecting the confidentiality or availability of the system. Organizations using this product are advised to assess their security measures to mitigate any potential risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP S/4HANA (Manage Bank Statements) S4CORE 107
SAP S/4HANA (Manage Bank Statements) 108
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved