
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-42957 is a critical ABAP code injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise) that allows an attacker with low-level user privileges to inject and execute arbitrary ABAP code via a function module exposed through Remote Function Call (RFC), bypassing essential authorization checks. The flaw was disclosed on August 12, 2025, as part of SAP's August 2025 Security Patch Day, and affects S4CORE versions 102, 103, 104, 105, 106, 107, and 108. It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity, and scope-changed nature (Red Hat Advisory, SAP Security Notes, Onapsis Blog).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerability exists in a function module exposed via RFC in SAP S/4HANA, where insufficient input validation and missing authorization checks allow a low-privileged authenticated user to supply arbitrary ABAP code that is subsequently executed by the system. Because the RFC-exposed function module does not enforce proper authorization controls, an attacker can craft malicious RFC calls to inject ABAP statements, effectively creating a persistent backdoor within the SAP environment. SecurityBridge, the firm credited with discovering the vulnerability, published a technical breakdown confirming the RFC attack vector and the authorization bypass mechanism (SecurityBridge Technical Breakdown, SecurityBridge Press Release, Onapsis Blog).
Successful exploitation grants an attacker with only basic user credentials the ability to execute arbitrary ABAP code with elevated privileges, resulting in full system compromise across all three security dimensions: confidentiality (unauthorized access to sensitive business data), integrity (modification or deletion of critical ERP data), and availability (disruption of SAP services). Because SAP S/4HANA systems typically serve as the backbone of enterprise operations — handling financials, supply chain, HR, and procurement — a compromise can enable lateral movement across connected SAP landscapes, data exfiltration, and persistent backdoor access. The vulnerability's changed scope means impact can extend beyond the directly compromised component to other systems integrated with the SAP environment (Feedly Intelligence, SecurityWeek, BleepingComputer).
SAP released the patch for CVE-2025-42957 in SAP Security Note 3627998 as part of the August 2025 Security Patch Day; organizations should apply this note immediately to all affected S4CORE versions (102–108) (SAP Security Notes, SAP Note 3627998). As interim workarounds prior to patching, organizations should implement strict access controls on RFC-exposed function modules, restrict network-level access to SAP RFC ports (typically TCP 33xx and 48xx) using firewalls or network segmentation, and monitor SAP security audit logs for authorization bypass attempts. Additionally, reviewing and tightening SAP user authorizations — particularly limiting which users can execute RFC calls — and enabling SAP Enterprise Threat Detection or equivalent SIEM monitoring for anomalous RFC activity are recommended defensive measures (Feedly Executive Summary, SecurityBridge Blog).
SecurityBridge, the firm that discovered and reported the vulnerability, published a detailed technical breakdown and press release highlighting the near-maximum severity and the speed at which exploitation followed public disclosure (SecurityBridge Press Release). The Hacker News, BleepingComputer, Dark Reading, The Register, Security Affairs, and SecurityWeek all covered the active exploitation, with widespread community concern expressed on Reddit (r/SAP, r/blueteamsec, r/ITManagers) about the gap between patch availability and exploitation onset. Multiple national CERTs — including Canada's CCCS (AV25-576), Austria's CERT.at, Singapore's CSA, Ireland's NCSC, and the Isle of Man's CSC — issued advisories urging immediate patching. The H-ISAC also issued a TLP:WHITE threat bulletin specifically addressing this vulnerability for the healthcare sector (Canadian CCCS, The Hacker News, Dark Reading).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."