← Back to browse · API

CVE-2025-27429

Severity
CRITICAL
CVSS
9.9
EPSS
0.00775
Risk score
39.87
CISA KEV
No
PoC
No
Published
2025-04-08
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-10103, GHSA-87HF-JHFP-WP4G
Products
SAP_SE:SAP S/4HANA (Private Cloud) 103, SAP_SE:SAP S/4HANA (Private Cloud) 104, SAP_SE:SAP S/4HANA (Private Cloud) 105, SAP_SE:SAP S/4HANA (Private Cloud) 106, SAP_SE:SAP S/4HANA (Private Cloud) 107, SAP_SE:SAP S/4HANA (Private Cloud) 108, SAP_SE:SAP S/4HANA (Private Cloud) S4CORE 102
Sources
euvd EUVD-2025-10103

Description

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

References