VYPR

S\/4hana Finance

by SAP

CVEs (5)

  • CVE-2024-21736MedJan 9, 2024
    risk 0.42cvss 6.4epss 0.00

    SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading to low impact on the confidentiality of…

  • CVE-2024-37172MedJul 9, 2024
    risk 0.35cvss 5.4epss 0.00

    SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity.

  • CVE-2026-76959MedSep 8, 2026
    risk 0.30cvss 4.6epss 0.00

    SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended…

  • CVE-2026-76961LowSep 8, 2026
    risk 0.23cvss 3.5epss 0.00

    SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended…

  • CVE-2026-76960LowSep 8, 2026
    risk 0.23cvss 3.5epss 0.00

    SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended…