First published: Tue Mar 11 2025(Updated: )
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted bank statement. This leads to a low impact on integrity, with no impact on the confidentiality of the data or the availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP S/4HANA Sales |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-27436 is classified as low.
To fix CVE-2025-27436, implement the recommended access control checks in your SAP S/4HANA system.
CVE-2025-27436 allows an authenticated user to delete attachments of posted bank statements, which can disrupt financial processes.
CVE-2025-27436 affects SAP S/4HANA.
Authenticated users with access to manage bank statements in SAP S/4HANA can exploit CVE-2025-27436.