cbcvebase.
CVE-2025-42887
published 2025-11-11

CVE-2025-42887: Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module…

PriorityP269critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.58%
44.0th percentile
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_solution_manager

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-42887 is exploitable by an authenticated attacker via a remote-enabled function module call in SAP Solution Manager — monitor for unusual RFC/remote function module invocations from authenticated sessions, especially those containing unsanitized or anomalous input payloads.
  • Exploitation of CVE-2025-42887 targets SAP Solution Manager specifically — prioritize monitoring and patching of SAP Solution Manager instances used for application lifecycle management in large enterprise SAP landscapes (ERP, CRM, analytics).
  • ·The vulnerability requires authentication — attack surface is limited to authenticated users/sessions, but successful exploitation grants full system control with high impact on confidentiality, integrity, and availability.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.