Impact
SAP S/4HANA Finance for Advanced Payment Management allows attackers to craft malicious links or pages that can trigger unintended actions when an authenticated user visits them. The flaw stems from insufficient CSRF safeguards on certain requests, enabling the attacker to perform operations on the web server with the victim’s privileges. The resulting compromise affects confidentiality and integrity at a low level, with no impact on availability.
Affected Systems
SAP S/4HANA Finance (Advanced Payment Management) is affected. Specific version information is not provided in the CVE data, so all deployments of this product that implement the vulnerable functionality may be impacted.
Risk and Exploitability
The CVSS score of 3.5 indicates a low overall severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. An attacker with low privileges can exploit the flaw by hosting a malicious link or page that, when clicked by an authenticated user, triggers actions on the server. The exploitation requires the victim to be authenticated and to interact with the crafted content, and the impact remains modest, affecting only confidentiality and integrity without disrupting availability.
OpenCVE Enrichment