Access Control Vulnerability in SAP S/4HANA for Bank Statement Management
CVE-2025-27436

4.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 March 2025

Summary

The Manage Bank Statements feature in SAP S/4HANA has been identified to lack essential access control checks for authenticated users. This oversight allows attackers to potentially delete attachments linked to submitted bank statements, which undermines the integrity of the bank statements without affecting the confidentiality or availability of the system. Organizations using this product are advised to assess their security measures to mitigate any potential risks associated with this vulnerability.

Affected Version(s)

SAP S/4HANA (Manage Bank Statements) S4CORE 107

SAP S/4HANA (Manage Bank Statements) 108

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.