CVE 4.3 MEDIUM

Missing Authorization Check in SAP S/4HANA (Manage Processing Rules – For Bank Statements)_CVE-2025-42939

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should be restricted, compromising the integrity of the application without affecting its confidentiality or availability.

Basic Information

ID CVE-2025-42939
Source sap
Published Oct 14, 2025 at 00:18

Affected Product

Vendor SAP_SE
Product SAP S/4HANA (Manage Processing Rules - For Bank Statements)
Version S4CORE 104
Affected Versions SAP_SE SAP S/4HANA (Manage Processing Rules - For Bank Statements) S4CORE 104
SAP_SE SAP S/4HANA (Manage Processing Rules - For Bank Statements) 105
SAP_SE SAP S/4HANA (Manage Processing Rules - For Bank Statements) 106
SAP_SE SAP S/4HANA (Manage Processing Rules - For Bank Statements) 107
SAP_SE SAP S/4HANA (Manage Processing Rules - For Bank Statements) 108
SAP_SE SAP S/4HANA (Manage Processing Rules - For Bank Statements) 109

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.