← Back to browse · API

CVE-2025-42950

Severity
CRITICAL
CVSS
9.9
EPSS
0.00657
Risk score
39.83
CISA KEV
No
PoC
No
Published
2025-08-12
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-24206, GHSA-48HJ-8597-5M47
Products
SAP_SE:SAP Landscape Transformation (Analysis Platform) 2011_1_710, SAP_SE:SAP Landscape Transformation (Analysis Platform) 2011_1_730, SAP_SE:SAP Landscape Transformation (Analysis Platform) 2011_1_731, SAP_SE:SAP Landscape Transformation (Analysis Platform) 2011_1_752, SAP_SE:SAP Landscape Transformation (Analysis Platform) 2020, SAP_SE:SAP Landscape Transformation (Analysis Platform) DMIS 2011_1_700
Sources
euvd EUVD-2025-24206

Description

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

References