cbcvebase.
CVE-2025-27429
published 2025-04-08

CVE-2025-27429: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of…

PriorityP268critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.76%
50.9th percentile
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

Affected

7 ranges
VendorProductVersion rangeFixed in
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-27429 is a code injection vulnerability in SAP S/4HANA exploited via a function module exposed over RFC (Remote Function Call), enabling injection of arbitrary ABAP code with bypassed authorization checks.
  • CVE-2025-27429 was patched in an out-of-band emergency SAP update released after the regular April 8, 2025 patch cycle; systems that applied only the April 2025 update remain vulnerable.
  • ·CVE-2025-27429 requires authenticated user privileges (not unauthenticated) to exploit — attackers must already have some level of user access to the SAP S/4HANA system before injecting ABAP code via RFC.
  • ·The sources do not name the specific vulnerable RFC function module for CVE-2025-27429; defenders should monitor all RFC-exposed function modules for anomalous ABAP injection patterns until the specific module is disclosed.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.