CVE-2025-27429
published 2025-04-08CVE-2025-27429: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of…
PriorityP268critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.76%
50.9th percentile
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-27429 is a code injection vulnerability in SAP S/4HANA exploited via a function module exposed over RFC (Remote Function Call), enabling injection of arbitrary ABAP code with bypassed authorization checks. ↗
- →CVE-2025-27429 was patched in an out-of-band emergency SAP update released after the regular April 8, 2025 patch cycle; systems that applied only the April 2025 update remain vulnerable. ↗
- ·CVE-2025-27429 requires authenticated user privileges (not unauthenticated) to exploit — attackers must already have some level of user access to the SAP S/4HANA system before injecting ABAP code via RFC. ↗
- ·The sources do not name the specific vulnerable RFC function module for CVE-2025-27429; defenders should monitor all RFC-exposed function modules for anomalous ABAP injection patterns until the specific module is disclosed. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2025-04-08
Published