CVE-2025-42967: Code Injection vulnerability in SAP S/4HANA and SAP SCM (Characteristic Propagation)
SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42967?
CVE-2025-42967 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2025-42967?
Fixing CVE-2025-42967 requires applying the latest security patch provided by SAP for both SAP S/4HANA and SAP SCM.
What types of systems are affected by CVE-2025-42967?
CVE-2025-42967 affects SAP S/4HANA and SAP SCM systems.
What can an attacker do with CVE-2025-42967?
An attacker exploiting CVE-2025-42967 can execute arbitrary code, potentially gaining full control over the affected SAP system.
Who is impacted by CVE-2025-42967?
Organizations using SAP S/4HANA and SAP SCM are impacted by CVE-2025-42967, especially those with high privileged user access.