CVE-2025-42957
published 2025-08-12CVE-2025-42957: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of…
PriorityP189critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
1.55%
72.4th percentile
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
| sap_se | sap_s_4hana | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Patch reversal is trivial for skilled attackers due to ABAP code visibility; treat any RFC-exposed function module call from low-privileged accounts with code-injection patterns as high-priority alert ↗
- →Monitor for post-exploitation indicators: new backdoor accounts, credential access, data exfiltration, and ransomware/malware deployment on SAP systems ↗
- →Exploitation demonstrated via OS command execution on SAP servers; monitor SAP application server OS-level process spawning from ABAP runtime processes ↗
- ·Affected products and versions are specifically enumerated; ensure detection and patching scope covers all listed versions ↗
- ·The vulnerability requires only low-privileged (user-level) authentication, significantly broadening the attacker surface compared to admin-only flaws ↗
- ·The patch was released August 11, 2025; exploitation is occurring against systems that have not applied the August 2025 Patch Day updates ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vulncheck9.9CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2c3g-27ww-4q84: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC
ghsa_unreviewed·2025-08-12
CVE-2025-42957 [CRITICAL] CWE-94 GHSA-2c3g-27ww-4q84: SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
VulnCheck
Improper Control of Generation of Code ('Code Injection')
vulncheck·2025·CVSS 9.9
CVE-2025-42957 [CRITICAL] Improper Control of Generation of Code ('Code Injection')
Improper Control of Generation of Code ('Code Injection')
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Affected: SAP S/4HANA
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securitybridge.com/blog/critical-sap-s-4hana-code-injection-vulnerability-cve-2025-42957/; https://pathlock.com/blog/s
No detection rules found.
No public exploits indexed.
Bleepingcomputer
SAP fixes three critical vulnerabilities across multiple products
blogs_bleepingcomputer·2025-12-09·CVSS 9.9
CVE-2025-42880 [CRITICAL] SAP fixes three critical vulnerabilities across multiple products
## SAP fixes three critical vulnerabilities across multiple products
## Bill Toulas
SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws.
The most severe (CVSS score: 9.9) of all the issues is CVE-2025-42880 , a code injection problem impacting SAP Solution Manager ST 720.
"Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module," reads the flaw's description.
"This could provide the attacker with full control of the system, hence leading to high impact on confidentiality, integrity, and availability of the system."
SAP Solution Manager is the vendor's central lifecycle management and monitori
Bleepingcomputer
SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor
blogs_bleepingcomputer·2025-11-11·CVSS 9.9
CVE-2025-42890 [CRITICAL] SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor
## SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor
## Bill Toulas
SAP has released its November security updates that address multiple security vulnerabilities, including a maximum severity flaw in the non-GUI variant of the SQL Anywhere Monitor and a critical code injection issue in the Solution Manager platform.
The security problem in SQL Anywhere Monitor is tracked as CVE-2025-42890 and consists of hardcoded credentials. Because of the elevated risk, the vulnerability received the maximum severity score of 10.0.
"SQL Anywhere Monitor (Non-GUI) baked credentials into the code, exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution," reads the description for the flaw.
Depending on how they ar
Bleepingcomputer
SAP fixes maximum severity NetWeaver command execution flaw
blogs_bleepingcomputer·2025-09-09·CVSS 9.9
[CRITICAL] SAP fixes maximum severity NetWeaver command execution flaw
## SAP fixes maximum severity NetWeaver command execution flaw
## Bill Toulas
SAP has addressed 21 new vulnerabilities affecting its products, including three critical severity issues impacting the NetWeaver software solution.
SAP NetWeaver is the foundation for SAP's business apps like ERP, CRM, SRM, and SCM, and acts as a modular middleware that is broadly deployed in large enterprise networks.
In its security bulletin for September, the provider of enterprise resource planning (ERP) software lists a vulnerability with a maximum severity score of 10 out of 10 that is identified as CVE-2025-42944 .
The security issue is an insecure deserialization vulnerability in SAP NetWeaver (RMIP4), ServerCore 7.50.
An unauthenticated attacker could exploit it to achieve arbitrary OS command exe
Bleepingcomputer
Critical SAP S/4HANA vulnerability now exploited in attacks
blogs_bleepingcomputer·2025-09-05·CVSS 9.9
CVE-2025-42957 [CRITICAL] Critical SAP S/4HANA vulnerability now exploited in attacks
## Critical SAP S/4HANA vulnerability now exploited in attacks
## Bill Toulas
A critical SAP S/4HANA code injection vulnerability is being leveraged in attacks in the wild to breach exposed servers, researchers warn.
The flaw, tracked as CVE-2025-42957 , is an ABAP code injection problem in an RFC-exposed function module of SAP S/4HANA, allowing low-privileged authentication users to inject arbitrary code, bypass authorization, and fully take over SAP.
The vendor fixed the vulnerability on August 11, 2025, rating it critical (CVSS score: 9.9).
However, several systems have not applied the available security updates, and these are now being targeted by hackers who have weaponized the bug.
According to a report by SecurityBridge, CVE-2025-42957 is now under active, albeit limited, expl
Wiz
CVE-2026-0498 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.5
CVE-2026-0498 [LOW] CVE-2026-0498 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0498 :
SAP S/4HANA vulnerability analysis and mitigation
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Source : NVD
## 7.2
Score
Published January 13, 2026
Severity HIGH
CNA Score 9.1
Affected Technologies
SAP S/4HANA
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.8
Exp
arXiv
Where Do LLM-based Systems Break? A System-Level Security Framework for Risk Assessment and Treatment
arxiv_fulltext·2026-03-08
Where Do LLM-based Systems Break? A System-Level Security Framework for Risk Assessment and Treatment
Where Do LLM-based Systems Break? A System-Level Security Framework for Risk Assessment and Treatment
Neha Nagaraja
School of Informatics, Computing, and Cyber Systems
Northern Arizona University
Flagstaff, USA
[email protected]
Hayretdin Bahsi1,2
1School of Informatics, Computing, and Cyber Systems
Northern Arizona University, Flagstaff, USA
2Department of Software Science
Tallinn University of Technology, Tallinn, Estonia
[email protected]
Abstract - Large Language Models (LLMs) are increasingly integrated into safety-critical workflows, yet existing security analyses remain fragmented and often isolate model behavior from the broader system context. This work introduces a goal-driven risk assessment framework for LLM-powered systems that combines system modeling with Attack–
2025-08-12
Published
Exploited in the wild