PT-2025-32613 · Sap · Sap S/4Hana

Published

2025-08-12

·

Updated

2025-09-08

·

CVE-2025-42957

CVSS v3.1
9.9
VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

SAP S/4HANA (affected versions not specified)

**Description:**

SAP S/4HANA is vulnerable to a critical flaw that allows an attacker with user privileges to exploit a vulnerability in a function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability functions as a backdoor, potentially leading to full system compromise, undermining the confidentiality, integrity, and availability of the system. The vulnerability is under active exploitation and has been observed in the wild. Approximately 440,000 organizations may be affected. Attackers require only low-level user access to potentially gain full control of the system, including the ability to create superusers, steal data, and even deploy ransomware.

**Recommendations:**

Apply SAP Security Notes 3627998 and 3633838 immediately.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-10538
CVE-2025-42957

Affected Products

Sap S/4Hana