CVE-2025-27433: SAP SE SAP s/4hana Manage Bank Statements

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity, with no effect on confidentiality and availability of the application.

Affected products

  • SAP SE SAP s/4hana Manage Bank Statements: version S4CORE 107 only; version 108 only

Published 2025-03-11. Last modified 2026-06-17.