cbcvebase.

Sap Se Sap S 4Hana vulnerabilities

33 known vulnerabilities affecting sap_se/sap_s_4hana.

Total CVEs
33
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH6MEDIUM23

Vulnerabilities

Page 1 of 2
CVE-2025-42957P1CRITICALCVSS 9.9ExploitedPoCvS4CORE 102v103+5 more2025-08-12
CVE-2025-42957 [CRITICAL] CWE-94 CVE-2025-42957: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function modul SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the
nvd
CVE-2025-27429P2CRITICALCVSS 9.9vS4CORE 102v103+5 more2025-04-08
CVE-2025-27429 [CRITICAL] CWE-94 CVE-2025-27429: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function modul SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the
nvd
CVE-2026-34260P3CRITICALCVSS 9.6vSAP_BASIS 751vSAP_BASIS 752+7 more2026-05-12
CVE-2026-34260 [CRITICAL] CWE-89 CVE-2026-34260: SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an a SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database without proper validation or sa
nvd
CVE-2021-38176P3HIGHCVSS 8.8fixed in 1511fixed in 1610+5 more2021-09-14
CVE-2021-38176 [HIGH] CWE-89 CVE-2021-38176: Due to improper input sanitization, an authenticated user with certain specific privileges can remot Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availab
nvd
CVE-2021-33701P3CRITICALCVSS 9.1fixed in SAPSCORE 125fixed in S4CORE 102+4 more2021-09-15
CVE-2021-33701 [CRITICAL] CWE-89 CVE-2021-33701: DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL
nvd
CVE-2026-0498P3HIGHCVSS 7.2vS4CORE 102v103+6 more2026-01-13
CVE-2026-0498 [HIGH] CWE-94 CVE-2026-0498: SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vul SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of fu
nvd
CVE-2022-22531P3HIGHCVSS 8.1v100v101+5 more2022-01-14
CVE-2022-22531 [HIGH] CVE-2022-22531: The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed or modified.
nvd
CVE-2022-22530P3HIGHCVSS 8.1v100v101+5 more2022-01-14
CVE-2022-22530 [HIGH] CVE-2022-22530: The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical information being modified or completely compromise the availability of the application.
nvd
CVE-2026-44744P3MEDIUMCVSS 6.5vS4FND 102v103+6 more2026-06-09
CVE-2026-44744 [MEDIUM] CWE-89 CVE-2026-44744: SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module com SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The vulnerability has a high impact on the confi
nvd
CVE-2025-42916P3HIGHCVSS 8.1vS4CORE 102v103+5 more2025-09-09
CVE-2025-42916 [HIGH] CWE-1287 CVE-2025-42916: Due to missing input validation, an attacker with high privilege access to ABAP reports could delete Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.
nvd
CVE-2023-35870P3HIGHCVSS 7.3vS4CORE 104v105+2 more2023-07-11
CVE-2023-35870 [HIGH] CWE-732 CVE-2023-35870: When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4C When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily
nvd
CVE-2025-42993P3MEDIUMCVSS 6.7vSAP_GWFND 757v7582025-06-10
CVE-2025-42993 [MEDIUM] CWE-862 CVE-2025-42993: Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an RFC destination and assign an arbitrary high-privilege user. This allows the attacker to consume events via the RFC destination, leading to code execution under the privileges of
nvd
CVE-2024-34691P3MEDIUMCVSS 6.5vS4CORE 102v103+5 more2024-06-11
CVE-2024-34691 [MEDIUM] CWE-862 CVE-2024-34691: Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no impact on the confidentiality and availability of the system.
nvd
CVE-2025-43003P3MEDIUMCVSS 6.4vS4CRM 204v205+7 more2025-05-13
CVE-2025-43003 [MEDIUM] CWE-749 CVE-2025-43003: SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout displaying this field. On performing this step the attacker could gain access to highly sensitive information. This could cause a high impact on confidentiality and minimal impact on integrity and availa
nvd
CVE-2025-42946P3MEDIUMCVSS 6.9vSAP_APPL 606vSAP_FIN 617+10 more2025-08-12
CVE-2025-42946 [MEDIUM] CWE-22 CVE-2025-42946: Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attacker to potentially read or delete these files hence cau
nvd
CVE-2022-31597P4MEDIUMCVSS 5.4vS4CORE 101v102+5 more2022-07-12
CVE-2022-31597 [MEDIUM] CWE-862 CVE-2022-31597: Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application bus Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the da
nvd
CVE-2025-42984P4MEDIUMCVSS 5.4vS4CORE 106v107+1 more2025-06-10
CVE-2025-42984 [MEDIUM] CWE-862 CVE-2025-42984: SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function import on the entity making it inaccessible for unrestricted user. This has low impact on confidentiality and availability of the application.
nvd
CVE-2022-32248P4MEDIUMCVSS 5.3v101v102+4 more2022-07-12
CVE-2022-32248 [MEDIUM] CWE-20 CVE-2022-32248: Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102 Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an impact on the integrity of the data.
nvd
CVE-2020-6199P4MEDIUMCVSS 5.4fixed in 100fixed in 101+3 more2020-03-10
CVE-2020-6199 [MEDIUM] CWE-862 CVE-2020-6199: The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN ver The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization group can maintain any company certificate, leading to
nvd
CVE-2023-40306P4MEDIUMCVSS 6.1v103v104+2 more2023-09-08
CVE-2023-40306 [MEDIUM] CWE-601 CVE-2023-40306: SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
nvd
Sap Se Sap S 4Hana vulnerabilities | cvebase