CVE-2025-42915: SAP SE Fiori App Manage Payment Blocks

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be restricted to specific user groups.This issue could impact both the confidentiality and integrity of the application without affecting the availability.

Affected products

  • SAP SE Fiori App Manage Payment Blocks: version S4CORE 107 only; version 108 only

Published 2025-09-09. Last modified 2026-06-17.