AI analysis
SAP S/4HANA Finance (Advanced Payment Management) fails to apply sufficient Cross-Site Request Forgery (CSRF, CWE-352) protection to certain requests in its web interface. An attacker who already holds low-privileged access can craft a malicious link or page, and when an authenticated victim interacts with it, unintended actions are executed on the web server on the victim's behalf. The result is a low impact on confidentiality and integrity with no impact on availability; CVSS 3.1 scores it 3.5 (Low). Only organizations running the Advanced Payment Management component of SAP S/4HANA Finance are affected. As of the advisory, there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, EPSS assigns roughly a 0.1% probability of exploitation within 30 days, and a fix was shipped as part of SAP's September 2026 security update.
What to do: Apply the security note released in SAP's September 2026 Patch Day for S/4HANA Finance (Advanced Payment Management) and verify the patched support package level against the official SAP advisory, since affected version ranges were not included in the data provided. Until patched, restrict the APM web interface to trusted internal networks and remind finance users not to follow unsolicited links while authenticated. No public exploit is known, so prompt patching and access restriction are sufficient.
Affected
| SAP S/4HANA Finance (Advanced Payment Management) | — |
Estimated exposure
nichelikely hundreds to a few thousand enterprise installations of the APM component (exact count unknown) — SAP S/4HANA runs at tens of thousands of customers, but Advanced Payment Management is a specialized finance add-on adopted by only a subset of large enterprises, and exploitation additionally requires the APM web UI to be reachable and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.