Authorization Issue in SAP S/4HANA for Bank Statements
CVE-2025-42939

4.3MEDIUM

What is CVE-2025-42939?

An authenticated attacker with basic privileges can exploit a missing authorization check in SAP S/4HANA's Manage Processing Rules for Bank Statements, allowing them to delete conditions from any user's shared rule. This manipulation compromises the application's integrity by enabling unauthorized changes without affecting confidentiality or availability, posing significant risks to data integrity. For more details, refer to SAP's security notes.

Affected Version(s)

SAP S/4HANA (Manage Processing Rules - For Bank Statements) S4CORE 104

SAP S/4HANA (Manage Processing Rules - For Bank Statements) 105

SAP S/4HANA (Manage Processing Rules - For Bank Statements) 106

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.