HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-27436
发布日期2025-03-11T00:39:14.372Z
更新日期2025-03-11T02:03:20.832Z
状态PUBLISHED
受影响的供应商SAP_SE
受影响的产品SAP S/4HANA (Manage Bank Statements)
描述The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted bank statement. This leads to a low impact on integrity, with no impact on the confidentiality of the data or the availability of the application.

参考链接:

Image Additional Image