cbcvebase.

Sap Se Sap S 4Hana vulnerabilities

33 known vulnerabilities affecting sap_se/sap_s_4hana.

Total CVEs
33
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH6MEDIUM23

Vulnerabilities

Page 2 of 2
CVE-2026-27673P4MEDIUMCVSS 4.9vS4CORE 105v106+7 more2026-04-14
CVE-2026-27673 [MEDIUM] CWE-862 CVE-2026-27673: Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authentic Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.
nvd
CVE-2025-42939P4MEDIUMCVSS 4.3vS4CORE 104v105+4 more2025-10-14
CVE-2025-42939 [MEDIUM] CWE-863 CVE-2025-42939: SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with ba SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should be restricted, compromising the integrity of the ap
nvd
CVE-2024-33002P4MEDIUMCVSS 6.1vSAP_BASIS 740vSAP_BASIS 750+8 more2024-05-14
CVE-2024-33002 [MEDIUM] CWE-79 CVE-2024-33002: Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-c Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
nvd
CVE-2020-6185P4MEDIUMCVSS 5.4v= 7.50v= 7.51+3 more2020-02-12
CVE-2020-6185 [MEDIUM] CWE-79 CVE-2020-6185: Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4 Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.
nvd
CVE-2020-6214P4MEDIUMCVSS 4.7fixed in 1002020-04-14
CVE-2020-6214 [MEDIUM] CWE-863 CVE-2020-6214: SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in s SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data, thereby preventing the proper segregation of duties in th
nvd
CVE-2025-27436P4MEDIUMCVSS 4.3vS4CORE 107v1082025-03-11
CVE-2025-27436 [MEDIUM] CWE-639 CVE-2025-27436: The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an aut The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted bank statement. This leads to a low impact on integrity, with no impact on the confidentiality of the da
nvd
CVE-2025-42987P4MEDIUMCVSS 4.3vS4CORE 104v105+3 more2025-06-10
CVE-2025-42987 [MEDIUM] CWE-862 CVE-2025-42987: SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit sh SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, compromising the integrity of the application.
nvd
CVE-2026-44771P4MEDIUMCVSS 4.3vS4CORE 1082026-07-14
CVE-2026-44771 [MEDIUM] CWE-862 CVE-2026-44771: SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated use SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
nvd
CVE-2025-27433P4MEDIUMCVSS 4.3vS4CORE 107v1082025-03-11
CVE-2025-27433 [MEDIUM] CWE-639 CVE-2025-27433: The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functional The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity, with no effect on confidentiality and availability of the application.
nvd
CVE-2025-42934P4MEDIUMCVSS 4.3vS4CORE 102v103+6 more2025-08-12
CVE-2025-42934 [MEDIUM] CWE-113 CVE-2025-42934: SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted Sites' configuration by injecting line feed (LF) characters into application inputs. This vulnerability has a low impact on the application's integrity and no impact on confidentia
nvd
CVE-2025-42991P4MEDIUMCVSS 4.3vS4CORE 1082025-06-10
CVE-2025-42991 [MEDIUM] CWE-862 CVE-2025-42991: SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'approver' user to delete attachment from bank account application of other user, leading to a low impact on integrity, with no impact on the confidentiality of the data or the availability of the application.
nvd
CVE-2025-23188P4MEDIUMCVSS 4.3vS4CORE 102v103+7 more2025-03-11
CVE-2025-23188 [MEDIUM] CWE-862 CVE-2025-23188: An authenticated user with low privileges can exploit a missing authorization check in an IBS module An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability.
nvd
CVE-2023-41369P4MEDIUMCVSS 4.3v100v101+7 more2023-09-12
CVE-2023-41369 [MEDIUM] CWE-611 CVE-2023-41369: The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 1 The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.
nvd
Sap Se Sap S 4Hana vulnerabilities | cvebase