CVE-2025-42887: Code Injection vulnerability in SAP Solution Manager
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42887?
CVE-2025-42887 is classified as a critical severity vulnerability due to its potential to allow full control of the SAP Solution Manager system.
How do I fix CVE-2025-42887?
To remediate CVE-2025-42887, ensure that all input sanitization is properly implemented in the affected remote-enabled function modules.
Who is affected by CVE-2025-42887?
SAP Solution Manager installations that allow for authenticated access are affected by CVE-2025-42887.
What are the potential impacts of CVE-2025-42887?
CVE-2025-42887 can lead to significant impacts on the confidentiality, integrity, and availability of data within the SAP Solution Manager.
Is there a patch available for CVE-2025-42887?
Yes, SAP provides security updates and patches to address CVE-2025-42887, which should be applied promptly.