CVE-2024-34691: SAP s/4 Hana

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no impact on the confidentiality and availability of the system.

Affected products

  • SAP s/4 Hana: version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; version 108 only; …

Published 2024-06-11. Last modified 2026-06-17.