SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should be restricted, compromising the integrity of the application without affecting its confidentiality or availability.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 14 Oct 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should be restricted, compromising the integrity of the application without affecting its confidentiality or availability. | |
Title | Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements) | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-10-14T00:18:39.026Z
Reserved: 2025-04-16T13:25:34.582Z
Link: CVE-2025-42939

No data.

Status : Received
Published: 2025-10-14T01:15:33.210
Modified: 2025-10-14T01:15:33.210
Link: CVE-2025-42939

No data.

No data.