CVE-2025-42880: Code Injection vulnerability in SAP Solution Manager
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42880?
CVE-2025-42880 is considered high severity due to its potential to allow full control of the system by an authenticated attacker.
How do I fix CVE-2025-42880?
To fix CVE-2025-42880, implement input sanitation measures and apply patches provided by SAP as soon as they are available.
What are the potential impacts of CVE-2025-42880?
The potential impacts of CVE-2025-42880 include compromised confidentiality and integrity of data in SAP Solution Manager.
Who is affected by CVE-2025-42880?
CVE-2025-42880 affects users of SAP Solution Manager who have not implemented proper input sanitation.
Is CVE-2025-42880 related to remote-enabled function modules?
Yes, CVE-2025-42880 involves vulnerabilities in remote-enabled function modules that can be exploited due to missing input sanitation.