VYPR

S\/4hana

by SAP

CVEs (61)

  • CVE-2026-27673MedApr 14, 2026
    risk 0.32cvss 4.9epss 0.00

    Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and…

  • CVE-2020-6214MedApr 14, 2020
    risk 0.31cvss 4.7epss 0.01

    SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change,…

  • CVE-2026-76962MedSep 8, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a…

  • CVE-2026-66764MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality,…

  • CVE-2026-27676MedApr 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability results in a low impact on integrity, while…

  • CVE-2025-42939MedOct 14, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule…

  • CVE-2025-42991MedJun 10, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'approver' user to delete attachment from bank account application of other user, leading to a low impact on integrity, with no impact on the confidentiality of…

  • CVE-2025-27436MedMar 11, 2025
    risk 0.28cvss 4.3epss 0.00

    The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted bank statement. This leads to a…

  • CVE-2025-27433MedMar 11, 2025
    risk 0.28cvss 4.3epss 0.00

    The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity, with no effect on…

  • CVE-2024-45282MedOct 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity…

  • CVE-2024-44121MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not impact the integrity and…

  • CVE-2024-30217MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the…

  • CVE-2024-30216MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of…

  • CVE-2023-42475MedOct 10, 2023
    risk 0.28cvss 4.3epss 0.00

    The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.

  • CVE-2020-6316MedNov 10, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

  • CVE-2020-6273MedAug 12, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.

  • CVE-2020-6233MedApr 14, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system.

  • CVE-2023-41369LowSep 12, 2023
    risk 0.23cvss 3.5epss 0.00

    The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause…

  • CVE-2023-41368LowSep 12, 2023
    risk 0.18cvss 2.7epss 0.00

    The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData call.

  • CVE-2026-44771MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity…