CVE-2025-42984: SAP SE SAP s/4hana Manage Central Purchase Contract Application

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function import on the entity making it inaccessible for unrestricted user. This has low impact on confidentiality and availability of the application.

Affected products

  • SAP SE SAP s/4hana Manage Central Purchase Contract Application: version S4CORE 106 only; version 107 only; version 108 only

Published 2025-06-10. Last modified 2026-06-17.