CVE-2025-42880
published 2025-12-09CVE-2025-42880: Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module…
PriorityP274critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
3.96%
89.3th percentile
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_solution_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target vector is a remote-enabled function module call in SAP Solution Manager ST 720; monitor RFC/function module invocations from authenticated users for unsanitized/malicious code injection payloads ↗
- →Successful exploitation grants full system control; alert on unexpected privilege escalation, new OS-level process spawning, or lateral movement originating from SAP Solution Manager host processes ↗
- ·Exploitation requires prior authentication; unauthenticated access alone is insufficient — focus detection on authenticated RFC/function module calls carrying anomalous payloads ↗
- ·SAP has not marked this vulnerability as actively exploited in the wild as of the December 2025 bulletin; no public PoC or threat-actor attribution is referenced in available sources ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
15th December – Threat Intelligence Report
blogs_checkpoint·2025-12-15
CVE-2025-14174 15th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th December, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The Indian government confirmed cyber incidents involving GPS spoofing at seven major airports, including Delhi, Mumbai, Kolkata, and Bengaluru. The attack affected aircrafts using GPS-based landing procedures. Despite signal disruption to navigation data, authorities stated no flights were cancelled or diverted, with c
Bleepingcomputer
SAP fixes three critical vulnerabilities across multiple products
blogs_bleepingcomputer·2025-12-09·CVSS 9.9
CVE-2025-42880 [CRITICAL] SAP fixes three critical vulnerabilities across multiple products
## SAP fixes three critical vulnerabilities across multiple products
## Bill Toulas
SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws.
The most severe (CVSS score: 9.9) of all the issues is CVE-2025-42880 , a code injection problem impacting SAP Solution Manager ST 720.
"Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module," reads the flaw's description.
"This could provide the attacker with full control of the system, hence leading to high impact on confidentiality, integrity, and availability of the system."
SAP Solution Manager is the vendor's central lifecycle management and monitori
2025-12-09
Published