PT-2025-28286 · Sap · Sap Scm Characteristic Propagation+1
Published
2025-07-08
·
Updated
2025-08-10
·
CVE-2025-42967
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP S/4HANA and SAP SCM versions S4CORE 102-108
Description
SAP S/4HANA and SAP SCM Characteristic Propagation contains a remote code execution issue. An attacker with user-level or high privileges can create a new report containing malicious code, potentially gaining full control of the affected SAP system. This can have a high impact on the confidentiality, integrity, and availability of the application. The vulnerability involves improper code generation management, allowing remote execution of arbitrary code through a specially crafted report.
Recommendations
SAP S/4HANA versions S4CORE 102 through 108: Update to patched versions immediately.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap S/4Hana
Sap Scm Characteristic Propagation