Authorization Issue in SAP S/4HANA for Bank Statements
CVE-2025-42939
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-42939?
An authenticated attacker with basic privileges can exploit a missing authorization check in SAP S/4HANA's Manage Processing Rules for Bank Statements, allowing them to delete conditions from any user's shared rule. This manipulation compromises the application's integrity by enabling unauthorized changes without affecting confidentiality or availability, posing significant risks to data integrity. For more details, refer to SAP's security notes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP S/4HANA (Manage Processing Rules - For Bank Statements) S4CORE 104
SAP S/4HANA (Manage Processing Rules - For Bank Statements) 105
SAP S/4HANA (Manage Processing Rules - For Bank Statements) 106
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved