← Back to browse · API

CVE-2025-42957

Severity
CRITICAL
CVSS
9.9
EPSS
0.01553
Risk score
40.14
CISA KEV
No
PoC
No
Published
2025-08-12
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-24203, GHSA-2C3G-27WW-4Q84
Products
SAP_SE:SAP S/4HANA (Private Cloud or On-Premise) 103, SAP_SE:SAP S/4HANA (Private Cloud or On-Premise) 104, SAP_SE:SAP S/4HANA (Private Cloud or On-Premise) 105, SAP_SE:SAP S/4HANA (Private Cloud or On-Premise) 106, SAP_SE:SAP S/4HANA (Private Cloud or On-Premise) 107, SAP_SE:SAP S/4HANA (Private Cloud or On-Premise) 108, SAP_SE:SAP S/4HANA (Private Cloud or On-Premise) S4CORE 102
Sources
euvd EUVD-2025-24203

Description

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

References