SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, compromising the integrity of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Jun 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, compromising the integrity of the application. | |
Title | Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statement) | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-06-10T00:11:45.597Z
Updated: 2025-06-10T15:15:47.066Z
Reserved: 2025-04-16T13:25:48.060Z
Link: CVE-2025-42987

Updated: 2025-06-10T13:27:21.759Z

Status : Awaiting Analysis
Published: 2025-06-10T01:15:21.860
Modified: 2025-06-12T16:06:39.330
Link: CVE-2025-42987

No data.