CVE-2025-42887
published 2025-11-11CVE-2025-42887: Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module…
PriorityP269critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.58%
44.0th percentile
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_solution_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-42887 is exploitable by an authenticated attacker via a remote-enabled function module call in SAP Solution Manager — monitor for unusual RFC/remote function module invocations from authenticated sessions, especially those containing unsanitized or anomalous input payloads. ↗
- →Exploitation of CVE-2025-42887 targets SAP Solution Manager specifically — prioritize monitoring and patching of SAP Solution Manager instances used for application lifecycle management in large enterprise SAP landscapes (ERP, CRM, analytics). ↗
- ·The vulnerability requires authentication — attack surface is limited to authenticated users/sessions, but successful exploitation grants full system control with high impact on confidentiality, integrity, and availability. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2025-11-11
Published