Security Advisory

CVE-2024-21736

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-01-09 01:15:17
Last updated 2025-04-17 17:59:58
Assigner sap
State PUBLISHED

Description

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading to low impact on the confidentiality of the application.