CVE-2025-27433Authorization Bypass Through User-Controlled Key in SE SAP S 4hana

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 75.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11

Description

The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity, with no effect on confidentiality and availability of the application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

CVEListV5sap_se/sap_s_4hana108, S4CORE 107+1

🔴Vulnerability Details

2
GHSA
GHSA-h4p3-cg85-78c7: The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload fil2025-03-11
CVEList
Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements)2025-03-11

📋Vendor Advisories

1
Microsoft
clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe()2024-05-14
CVE-2025-27433 — SAP SE SAP S 4hana vulnerability | cvebase