CVE-2025-42946: SAP SE SAP s/4hana Bank Communication Management

Medium severity, CVSS 6.9. EPSS: 1% chance of exploitation in the next 30 days.

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attacker to potentially read or delete these files hence causing a high impact on confidentiality and low impact on integrity. There is no impact on availability of the system.

Affected products

  • SAP SE SAP s/4hana Bank Communication Management: version 618 only; version 720 only; version 730 only; version S4CORE 102 only; version 103 only; version 104 only; …

Published 2025-08-12. Last modified 2026-06-17.