CVE-2023-41369: SAP s/4 Hana

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.

Affected products

  • SAP s/4 Hana: version 100 only; version 101 only; version 102 only; version 103 only; version 104 only; version 105 only; …

Published 2023-09-12. Last modified 2026-06-17.