[CVE-2026-76959] SAP S/4HANA Finance (Advanced Payment Management) does not p

CVE-2026-76959 | CVSS: 4.6 | 严重级别: MEDIUM

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

参考链接:
https://me.sap.com/notes/3365311
https://url.sap/sapsecuritypatchday

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部