CVE-2025-42957
SAP S/4HANA vulnerability analysis and mitigation

Overview

CVE-2025-42957 is a critical ABAP code injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise) that allows an attacker with low-level user privileges to inject and execute arbitrary ABAP code via a function module exposed through Remote Function Call (RFC), bypassing essential authorization checks. The flaw was disclosed on August 12, 2025, as part of SAP's August 2025 Security Patch Day, and affects S4CORE versions 102, 103, 104, 105, 106, 107, and 108. It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity, and scope-changed nature (Red Hat Advisory, SAP Security Notes, Onapsis Blog).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerability exists in a function module exposed via RFC in SAP S/4HANA, where insufficient input validation and missing authorization checks allow a low-privileged authenticated user to supply arbitrary ABAP code that is subsequently executed by the system. Because the RFC-exposed function module does not enforce proper authorization controls, an attacker can craft malicious RFC calls to inject ABAP statements, effectively creating a persistent backdoor within the SAP environment. SecurityBridge, the firm credited with discovering the vulnerability, published a technical breakdown confirming the RFC attack vector and the authorization bypass mechanism (SecurityBridge Technical Breakdown, SecurityBridge Press Release, Onapsis Blog).

Impact

Successful exploitation grants an attacker with only basic user credentials the ability to execute arbitrary ABAP code with elevated privileges, resulting in full system compromise across all three security dimensions: confidentiality (unauthorized access to sensitive business data), integrity (modification or deletion of critical ERP data), and availability (disruption of SAP services). Because SAP S/4HANA systems typically serve as the backbone of enterprise operations — handling financials, supply chain, HR, and procurement — a compromise can enable lateral movement across connected SAP landscapes, data exfiltration, and persistent backdoor access. The vulnerability's changed scope means impact can extend beyond the directly compromised component to other systems integrated with the SAP environment (Feedly Intelligence, SecurityWeek, BleepingComputer).

Exploitation steps

  1. Reconnaissance: Identify SAP S/4HANA instances (versions S4CORE 102–108) exposed to the network, particularly those with RFC services accessible. Tools such as Shodan or SAP-specific scanners can identify exposed RFC gateways or SAP Message Servers.
  2. Obtain low-privileged credentials: Acquire any valid SAP user account — even a basic dialog user — through phishing, credential stuffing, or purchasing from initial access brokers. No elevated SAP roles are required.
  3. Identify the vulnerable RFC function module: Using an RFC client (e.g., SAP GUI, pyrfc, or custom tooling), enumerate available RFC-exposed function modules to locate the vulnerable one that lacks proper authorization checks.
  4. Craft malicious RFC call: Construct an RFC call to the vulnerable function module, embedding arbitrary ABAP code as a parameter. The function module fails to validate or sanitize this input before executing it.
  5. Execute arbitrary ABAP code: The injected ABAP code executes within the SAP application server context, bypassing authorization checks. This can be used to create backdoor users, exfiltrate data via RFC or HTTP, modify business-critical records, or establish persistent access.
  6. Establish persistence: Use the injected code to create a new SAP user with administrator privileges, install a persistent ABAP backdoor program, or schedule background jobs for continued access (SecurityBridge Technical Breakdown, PoC GitHub, BleepingComputer).

Indicators of compromise

  • Network: Unusual or unexpected RFC calls to the vulnerable function module from low-privileged user accounts; RFC connections originating from unexpected IP addresses or external networks; elevated volume of RFC traffic to SAP application servers.
  • Logs: SAP system logs (SM21) showing execution of ABAP code from unexpected sources or users; authorization check bypass events in security audit logs (SM19/SM20); unexpected RFC function module calls in RFC trace logs; new background job creation by non-administrative users.
  • SAP Application: Newly created SAP user accounts with elevated profiles (e.g., SAP_ALL) not provisioned through normal processes; unexpected changes to ABAP programs or function modules in production; unauthorized modifications to critical business data tables.
  • Process/System: Unexpected outbound network connections from the SAP application server to external IPs; unusual ABAP program execution in background work processes; changes to system parameters or security-relevant configuration without change management records (SecurityBridge Technical Breakdown, BleepingComputer).

Mitigation and workarounds

SAP released the patch for CVE-2025-42957 in SAP Security Note 3627998 as part of the August 2025 Security Patch Day; organizations should apply this note immediately to all affected S4CORE versions (102–108) (SAP Security Notes, SAP Note 3627998). As interim workarounds prior to patching, organizations should implement strict access controls on RFC-exposed function modules, restrict network-level access to SAP RFC ports (typically TCP 33xx and 48xx) using firewalls or network segmentation, and monitor SAP security audit logs for authorization bypass attempts. Additionally, reviewing and tightening SAP user authorizations — particularly limiting which users can execute RFC calls — and enabling SAP Enterprise Threat Detection or equivalent SIEM monitoring for anomalous RFC activity are recommended defensive measures (Feedly Executive Summary, SecurityBridge Blog).

Community reactions

SecurityBridge, the firm that discovered and reported the vulnerability, published a detailed technical breakdown and press release highlighting the near-maximum severity and the speed at which exploitation followed public disclosure (SecurityBridge Press Release). The Hacker News, BleepingComputer, Dark Reading, The Register, Security Affairs, and SecurityWeek all covered the active exploitation, with widespread community concern expressed on Reddit (r/SAP, r/blueteamsec, r/ITManagers) about the gap between patch availability and exploitation onset. Multiple national CERTs — including Canada's CCCS (AV25-576), Austria's CERT.at, Singapore's CSA, Ireland's NCSC, and the Isle of Man's CSC — issued advisories urging immediate patching. The H-ISAC also issued a TLP:WHITE threat bulletin specifically addressing this vulnerability for the healthcare sector (Canadian CCCS, The Hacker News, Dark Reading).

Additional resources


SourceThis report was generated using AI

Related SAP S/4HANA vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-42957CRITICAL9.9
  • SAP S/4HANA logoSAP S/4HANA
  • cpe:2.3:a:sap:s\/4_hana
NoNoAug 12, 2025
CVE-2026-0498HIGH7.2
  • SAP S/4HANA logoSAP S/4HANA
  • cpe:2.3:a:sap:s\/4_hana
NoNoJan 13, 2026
CVE-2024-34691MEDIUM6.5
  • SAP S/4HANA logoSAP S/4HANA
  • cpe:2.3:a:sap:s\/4_hana
NoNoJun 11, 2024
CVE-2024-45282MEDIUM5.3
  • SAP S/4HANA logoSAP S/4HANA
  • cpe:2.3:a:sap:s\/4_hana
NoNoOct 08, 2024
CVE-2023-41369MEDIUM4.3
  • Python logoPython
  • cpe:2.3:a:sap:s\/4_hana
NoNoSep 12, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management