#VU114889 Path traversal in SAP S/4HANA - CVE-2025-42946
Published: September 6, 2025
SAP S/4HANA
SAP
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the Bank Communication Management component. A remote privileged user can send a specially crafted HTTP request and read arbitrary files on the system.