Authorization Issue in SAP S/4HANA for Bank Statements
CVE-2025-42939
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-42939?
An authenticated attacker with basic privileges can exploit a missing authorization check in SAP S/4HANA's Manage Processing Rules for Bank Statements, allowing them to delete conditions from any user's shared rule. This manipulation compromises the application's integrity by enabling unauthorized changes without affecting confidentiality or availability, posing significant risks to data integrity. For more details, refer to SAP's security notes.
Affected Version(s)
SAP S/4HANA (Manage Processing Rules - For Bank Statements) S4CORE 104
SAP S/4HANA (Manage Processing Rules - For Bank Statements) 105
SAP S/4HANA (Manage Processing Rules - For Bank Statements) 106