PT-2025-32613 · Sap · Sap S/4Hana
Published
2025-08-12
·
Updated
2025-09-08
·
CVE-2025-42957
9.9
Critical
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
SAP S/4HANA (affected versions not specified)
**Description:**
SAP S/4HANA is vulnerable to a critical flaw that allows an attacker with user privileges to exploit a vulnerability in a function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability functions as a backdoor, potentially leading to full system compromise, undermining the confidentiality, integrity, and availability of the system. The vulnerability is under active exploitation and has been observed in the wild. Approximately 440,000 organizations may be affected. Attackers require only low-level user access to potentially gain full control of the system, including the ability to create superusers, steal data, and even deploy ransomware.
**Recommendations:**
Apply SAP Security Notes 3627998 and 3633838 immediately.
Fix
Code Injection
Weakness Enumeration
Related Identifiers
Affected Products
References · 116
- https://bdu.fstec.ru/vul/2025-10538 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-42957 · Security Note
- https://twitter.com/Guardian360nl/status/1965082711812460558 · Twitter Post
- https://twitter.com/Dinosn/status/1963941641607082015 · Twitter Post
- https://twitter.com/chundefined/status/1963935346409750628 · Twitter Post
- https://twitter.com/shah_sheikh/status/1963931411364159514 · Twitter Post
- https://twitter.com/Newtalics/status/1964085208170328454 · Twitter Post
- https://twitter.com/buzz_sec/status/1963931576221196756 · Twitter Post
- https://twitter.com/IntCyberDigest/status/1964336125222265330 · Twitter Post
- https://reddit.com/r/TechNadu/comments/1n9t21e/sap_s4hana_flaw_cve202542957_cvss_99_is_now_being · Reddit Post
- https://twitter.com/_securitybridge/status/1963585384211759530 · Twitter Post
- https://twitter.com/Info_Sec_Buzz/status/1964969290047914330 · Twitter Post
- https://twitter.com/DaustoC/status/1964304974143246415 · Twitter Post
- https://twitter.com/cyber_megan/status/1964283528012497345 · Twitter Post
- https://twitter.com/fr3ak_hacks/status/1963955187141492830 · Twitter Post