VYPR

S/4HANA (Enterprise Event Enablement)

by SAP

CVEs (1)

  • CVE-2025-42993MedJun 10, 2025
    risk 0.44cvss 6.7epss 0.00

    Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an RFC destination and assign an arbitrary high-privilege user. This allows the attacker to consume events…