SAP S/4HANA Supplier invoice
cpe:2.3:a:sap:s4hana_sales:*:*:*:*:*:*:*
A CRLF injection vulnerability has been identified in SAP S/4HANA Supplier Invoice. This issue allows an attacker with user-level privileges to bypass the allowlist and inject untrusted sites into the 'Trusted Sites' configuration by adding line feed characters into application inputs. The vulnerability impacts the application's integrity, but does not affect confidentiality or availability.
Exploitation of this vulnerability could lead to unauthorized modification of the 'Trusted Sites' configuration, allowing the injection of untrusted sites.
Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP Security Patch Day Bulletin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.