CVE-2025-42987

SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, compromising the integrity of the application.
Configurations

No configuration.

History

12 Jun 2025, 16:06

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 01:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-42987

Mitre link : CVE-2025-42987

CVE.ORG link : CVE-2025-42987


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization