SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should be restricted, compromising the integrity of the application without affecting its confidentiality or availability.
History

Tue, 14 Oct 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should be restricted, compromising the integrity of the application without affecting its confidentiality or availability.
Title Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-10-14T00:18:39.026Z

Reserved: 2025-04-16T13:25:34.582Z

Link: CVE-2025-42939

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-14T01:15:33.210

Modified: 2025-10-14T01:15:33.210

Link: CVE-2025-42939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.