Impact
A cross‑site request forgery flaw in SAP S/4HANA Finance (Advanced Payment Management) allows an attacker with low privileges to create a malicious link or page that, when visited by an authenticated user, triggers unintended state‑changing requests on the web server. The vulnerability does not compromise data confidentiality or system availability, but it may result in unauthorized or accidental changes to financial data, which is captured as a low‑severity confidentiality/integrity impact.
Affected Systems
The affected product is SAP S/4HANA Finance (Advanced Payment Management) from SAP SE. No specific version information is provided in the data, so all installations of this product should be considered potentially exposed until an update is applied.
Risk and Exploitability
The CVSS score of 3.5 reflects a low overall risk. EPSS information is currently unavailable, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is a web‑based request that requires a victim to be authenticated in the target system; thus the attack can be executed over the network by delivering a malicious link or page. If successful, the effect is limited to unauthorized, low‑gravity business actions rather than catastrophic data loss or downtime.
OpenCVE Enrichment