cbcvebase.
CVE-2025-42957
published 2025-08-12

CVE-2025-42957: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of…

PriorityP189critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
1.55%
72.4th percentile
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

Affected

7 ranges
VendorProductVersion rangeFixed in
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana

Detection & IOCsextracted from sources · hover to see the quote

  • Patch reversal is trivial for skilled attackers due to ABAP code visibility; treat any RFC-exposed function module call from low-privileged accounts with code-injection patterns as high-priority alert
  • Monitor for post-exploitation indicators: new backdoor accounts, credential access, data exfiltration, and ransomware/malware deployment on SAP systems
  • Exploitation demonstrated via OS command execution on SAP servers; monitor SAP application server OS-level process spawning from ABAP runtime processes
  • ·Affected products and versions are specifically enumerated; ensure detection and patching scope covers all listed versions
  • ·The vulnerability requires only low-privileged (user-level) authentication, significantly broadening the attacker surface compared to admin-only flaws
  • ·The patch was released August 11, 2025; exploitation is occurring against systems that have not applied the August 2025 Patch Day updates

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vulncheck9.9CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.