CVE-2023-40625: SAP s4core

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system.

Affected products

  • SAP s4core: version 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only

Published 2023-09-12. Last modified 2026-06-17.