CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-27436
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%
Original NVD Description
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted bank statement. This leads to a low impact on integrity, with no impact on the confidentiality of the data or the availability of the application.