Medium severity6.4NVD Advisory· Published Jan 9, 2024· Updated Jun 17, 2026
CVE-2024-21736
CVE-2024-21736
Description
SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading to low impact on the confidentiality of the application.
Affected products
4cpe:2.3:a:sap:s\/4hana_finance:107:*:*:*:s4core:*:*:*+ 1 more
- cpe:2.3:a:sap:s\/4hana_finance:107:*:*:*:s4core:*:*:*
- cpe:2.3:a:sap:s\/4hana_finance:128:*:*:*:sapscore:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: SAPSCORE 128
Patches
Vulnerability mechanics
References
2- me.sap.com/notes/3260667nvdPermissions Required
- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdProduct
News mentions
0No linked articles in our index yet.