VYPR

S4CORE

by SAP

CVEs (2)

  • CVE-2025-42899MedNov 11, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This has low impact on confidentiality of the application with no impact on integrity and availability of the application.

  • CVE-2025-43002MedMay 13, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted.