Impact
This vulnerability stems from a missing authorization check in the SAP S/4HANA Manage Bank Chains application. A user with low privileges can construct specially crafted requests that trigger deletion of bank chain entries normally protected from that user. The loss of those entries constitutes a small availability impact; no confidential data is exposed and integrity is not compromised beyond the accidental removal of records.
Affected Systems
The issue affects SAP S/4HANA applications that provide the Manage Bank Chains functionality. No specific release numbers are listed in the CVE, so all deployments of the listed component are potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates this issue is considered low severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation is low. Attacks would require an authenticated user with at least low‑level access to the application; the attacker would then send crafted API or web requests to invoke the vulnerable delete operation. Successful exploitation would remove specific bank chain records, thus reducing service availability for the affected entities.
OpenCVE Enrichment