Impact
The flaw is a missing authorization check in SAP S/4 HANA’s Create Single Payment transaction, allowing an authenticated user to view entity set keys that should be protected. This flaw only affects the confidentiality of data, with no impact on integrity or availability. The vulnerability is identified as CWE‑862 and results in low‑impact information exposure.
Affected Systems
The vulnerability affects SAP S/4 HANA systems that expose the Create Single Payment functionality. No specific version numbers are listed in the CVE data, so the issue applies to all deployments that have not yet applied the appropriate SAP security patch.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, reflecting the limited confidentiality impact. The EPSS score is < 1%, indicating an extremely low probability of exploitation, and the vulnerability is not included in the CISA KEV catalog, suggesting no confirmed widespread exploitation. Exploitation requires an authenticated session in SAP S/4 HANA; an attacker can use the Create Single Payment transaction to read unauthorized data but cannot modify or disrupt the system. The risk is higher when sensitive data is handled and user roles are not tightly managed.
OpenCVE Enrichment