Impact
The vulnerability allows an attacker with low privileges to forge authenticated requests by omitting CSRF protection. If an authenticated SAP S/4HANA Finance user follows a crafted link or visits a malicious page, the system will execute unintended requests on behalf of the victim. The resulting data and process changes are limited, affecting only confidentiality and integrity in a low‑impact manner, with no effect on availability.
Affected Systems
The affected system is SAP S/4HANA Finance for Advanced Payment Management. No specific version information is disclosed in the advisory, so all installations running this module should be considered potentially vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate risk, but the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting a lower likelihood of exploitation. The attack requires the victim to be authenticated and interact with a malicious request, so the vector is user‑initiated via a crafted link or web page. The absence of a publicly documented exploit pathway means operators should treat this as a low‑to‑moderate risk pending patch availability.
OpenCVE Enrichment