AI analysis
SAP S/4HANA Finance (Advanced Payment Management) does not sufficiently protect certain requests against cross-site request forgery (CWE-352). An attacker with low privileges can craft a malicious link or web page, and when an authenticated user interacts with it, the browser issues requests that trigger unintended actions on the web server on the victim's behalf. Successful abuse yields a low impact on confidentiality and integrity, with no impact on availability. Any organization running the Advanced Payment Management component of SAP S/4HANA Finance is affected, with risk concentrated among finance and back-office users who browse other sites while authenticated to the application. There is no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.1% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Determine whether the Advanced Payment Management component is deployed in your SAP S/4HANA Finance landscape and apply the corresponding SAP security note from the September 2026 Patch Day release. Until patched, limit access to the application to necessary finance personnel and caution users about interacting with unsolicited links or pages while authenticated; no other workarounds are documented in the available data.
Affected
| SAP S/4HANA Finance (Advanced Payment Management) | — |
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (exact count unknown) — SAP S/4HANA has a very large enterprise installed base, but Advanced Payment Management is a specialized finance subcomponent deployed by only a subset of customers, typically on internal networks rather than internet-facing systems, so…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.