CVE Tools

Sap S/4 Hana

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Sap S/4 Hana, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Sap S/4 Hana CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Sap S/4 Hana CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-032
2025-042
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical16%
  • High16%
  • Medium1583%
  • Low16%

Latest CVEs

The 15 most recently published vulnerabilities affecting Sap S/4 Hana.

  1. CVE-2025-42876Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)7.1
  2. CVE-2025-42899Missing Authorization check in SAP S4CORE (Manage Journal Entries)4.3
  3. CVE-2025-31328Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution)4.6
  4. CVE-2025-31327OData meta-data property entity tampering in SAP Field Logistics4.3
  5. CVE-2025-27433Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements)4.3
  6. CVE-2025-27430Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)3.5
  7. CVE-2024-45282HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)4.3
  8. CVE-2024-34691Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)6.5
  9. CVE-2023-42475Information Disclosure Vulnerability in Statutory Reporting4.3
  10. CVE-2023-42473Missing Authorization Check In S/4HANA (Manage Withholding Tax Items)5.4
  11. CVE-2023-40306URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)6.1
  12. CVE-2023-35870Improper Access Control in SAP S/4HANA (Manage Journal Entry Template)6.3
  13. CVE-2022-32248Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the data...5.3
  14. CVE-2022-31597Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a ...5.4
  15. CVE-2021-33701DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105,...9.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store