SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap S/4hana (finance For Advanced Payment Management) |
|
| Vendors & Products |
Sap Se
Sap Se sap S/4hana (finance For Advanced Payment Management) |
Tue, 08 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability. | |
| Title | Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2026-09-08T00:12:01.156Z
Updated: 2026-09-09T13:14:25.266Z
Reserved: 2026-08-20T05:15:36.823Z
Link: CVE-2026-76961
Updated: 2026-09-08T10:32:20.670Z
Status : Awaiting Analysis
Published: 2026-09-08T01:17:54.793
Modified: 2026-09-09T14:17:16.793
Link: CVE-2026-76961
No data.