CVE-2025-42957: Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42957?
CVE-2025-42957 is considered a critical vulnerability due to its potential to allow arbitrary ABAP code injection.
How do I fix CVE-2025-42957?
To remediate CVE-2025-42957, apply the latest security patches provided by SAP for S/4HANA.
Who is affected by CVE-2025-42957?
CVE-2025-42957 affects users of SAP S/4HANA with access to the exposed function module via RFC.
What type of attack can be performed using CVE-2025-42957?
An attacker can exploit CVE-2025-42957 to inject arbitrary ABAP code, bypassing authorization checks.
Is there a known exploit for CVE-2025-42957?
As of now, there are no known public exploits for CVE-2025-42957, but it remains a serious security concern.