Home

Description

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-09 | Updated 2025-12-09 | Assigner sap




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Problem types

CWE-405: Asymmetric Resource Consumption

Product status

Default status
unaffected

S4CORE 104
affected

105
affected

106
affected

107
affected

108
affected

109
affected

References

me.sap.com/notes/3672151

url.sap/sapsecuritypatchday

cve.org (CVE-2025-42876)

nvd.nist.gov (CVE-2025-42876)

Download JSON