Access Control Vulnerability in SAP S/4HANA for Bank Statement Management
CVE-2025-27436
4.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 11 March 2025
Summary
The Manage Bank Statements feature in SAP S/4HANA has been identified to lack essential access control checks for authenticated users. This oversight allows attackers to potentially delete attachments linked to submitted bank statements, which undermines the integrity of the bank statements without affecting the confidentiality or availability of the system. Organizations using this product are advised to assess their security measures to mitigate any potential risks associated with this vulnerability.
Affected Version(s)
SAP S/4HANA (Manage Bank Statements) S4CORE 107
SAP S/4HANA (Manage Bank Statements) 108
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved