SAP S/4HANA Manage Bank Statements Functionality Bypass Vulnerability

Vulnerability

A vulnerability in the Manage Bank Statements feature of SAP S/4HANA allows authenticated attackers to bypass certain application functionality restrictions and upload files to a reversed bank statement. This issue impacts the application's integrity, while leaving confidentiality and availability unaffected.

Impact

Exploitation of this vulnerability allows for unauthorized file uploads to reversed bank statements, potentially leading to integrity issues within the application.

Remediation

Users are advised to review the SAP Security Notes related to this vulnerability and implement the recommended patches. SAP Security Notes can be accessed through the SAP for Me platform.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.6
exploitability
4.9
remediation
6.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.