The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's integrity, with no effect on confidentiality and availability of the application.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.