Impact
The vulnerability lies in the Reprocess Bank Statement Items function of SAP S/4 HANA, where an authenticated user fails to trigger the required authorization checks. As a result, users may apply processing rules that have never been shared with them, which allows them to elevate their privileges within the application. The impact on confidentiality is low, and there is no observable effect on the application's integrity or availability.
Affected Systems
SAP S/4 HANA instances that expose the Reprocess Bank Statement Items feature are impacted, specifically services provided by SAP SE under the product name SAP S/4 HANA (Reprocess Bank Statement Items). No version range was supplied in the CNA data, so the vulnerability may affect any deployed instance that has not applied the relevant SAP note 3669608.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability presents a moderate risk profile. The EPSS score is not available, and it is not included in CISA’s KEV catalog, suggesting limited public exploitation data. The likely attack path requires a legitimate user who has permission to invoke the reprocess function; the vulnerability is therefore exploitable in a privileged context rather than remotely. The lack of authorization checks means that any authorized user can increase their privileges by leveraging unapproved rules, but the impact does not extend beyond the application’s own data space. The overall threat is considered moderate, with a realistic but not imminent exploitation risk.
OpenCVE Enrichment