PT-2025-32613 · Sap · Sap S/4Hana

Published

2025-08-12

·

Updated

2025-10-09

·

CVE-2025-42957

CVSS v3.1
9.9
VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP S/4HANA versions prior to August 2025
Description SAP S/4HANA contains a critical vulnerability that allows an attacker with user privileges to exploit a flaw in a function module exposed via RFC. This allows the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This effectively functions as a backdoor, potentially leading to full system compromise, impacting confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, and successful exploitation can grant attackers full system control, enabling actions such as creating superusers, stealing data, and deploying ransomware. The vulnerability is tracked as CVE-2025-42957 and has a CVSS score of 9.9. It affects S/4HANA, DMIS, Business One, and NetWeaver.
Recommendations Apply SAP Security Notes 3627998 and 3633838 immediately.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-10538
CVE-2025-42957

Affected Products

Sap S/4Hana