CVE-2025-27436: Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements)
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted bank statement. This leads to a low impact on integrity, with no impact on the confidentiality of the data or the availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27436?
The severity of CVE-2025-27436 is classified as low.
How do I fix CVE-2025-27436?
To fix CVE-2025-27436, implement the recommended access control checks in your SAP S/4HANA system.
What are the potential impacts of CVE-2025-27436?
CVE-2025-27436 allows an authenticated user to delete attachments of posted bank statements, which can disrupt financial processes.
Which software is affected by CVE-2025-27436?
CVE-2025-27436 affects SAP S/4HANA.
Who can exploit CVE-2025-27436?
Authenticated users with access to manage bank statements in SAP S/4HANA can exploit CVE-2025-27436.