CVE-2025-42887Code Injection in SE SAP Solution Manager

CWE-94Code Injection3 documents3 sources
Severity
9.9CRITICALNVD
EPSS
0.1%
top 82.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 11

Description

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 3.1 | Impact: 6.0

Affected Packages1 packages

CVEListV5sap_se/sap_solution_managerST 720

🔴Vulnerability Details

2
CVEList
Code Injection vulnerability in SAP Solution Manager2025-11-11
GHSA
GHSA-cqr5-w9rg-4vm5: Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function2025-11-11
CVE-2025-42887 — Code Injection | cvebase