CVE-2025-27433: Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements)
Published Mar 11, 2025
·Updated
The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity, with no effect on confidentiality and availability of the application.
Affected Software
1 affected component
SAP S/4HANA
Event History
Mar 11, 2025
CVE Published
via MITRE·12:38 AM
Data Sourced
via MITRE·12:38 AM
DescriptionSeverity
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Nov 18, 57181
Event
via FIRST·01:02 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-27433?
CVE-2025-27433 has a low impact on the application's integrity.
2
How do I fix CVE-2025-27433?
To mitigate CVE-2025-27433, implement the latest patches and updates provided by SAP for S/4HANA.
3
What does CVE-2025-27433 allow an attacker to do?
CVE-2025-27433 allows an authenticated attacker to bypass certain functionality restrictions and upload files to a reversed bank statement.
4
Which software is affected by CVE-2025-27433?
CVE-2025-27433 specifically affects SAP S/4HANA.
5
Is there any effect on confidentiality due to CVE-2025-27433?
No, CVE-2025-27433 does not affect the confidentiality of the application's data.