Critical SAP S/4HANA flaw CVE-2025-42957 under active exploitation


Critical SAP S/4HANA flaw CVE-2025-42957 under active exploitation

Pierluigi Paganini
September 05, 2025

Experts warn of an actively exploited vulnerability, tracked as CVE-2025-42957 (CVSS score: 9.9), in SAP S/4HANA software.

A critical command injection vulnerability, tracked as CVE-2025-42957 (CVSS score of 9.9), in SAP S/4HANA is under active exploitation.

An attacker can exploit this flaw to fully compromise SAP systems, altering databases, creating superuser accounts, and stealing password hashes.

“SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks.” reads the advisory. “This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.”

SAP S/4HANA ERP is SAP’s enterprise resource planning (ERP) suite, designed to help large and mid-sized organizations manage core business processes like finance, supply chain, manufacturing, sales, procurement, and human resources.

The flaw affects all SAP S/4HANA releases (Private Cloud and On-Premise) and can be exploited from a low-privileged account to fully compromise the system.

The vendor addressed the vulnerability on August 11, 2025.

SecurityBridge Threat Research Labs found and confirmed an exploit for this issue that is active in the wild, recommending admins to immediately address the flaw.

“A complete system compromise with minimal effort required, where successful exploitation can easily lead to fraud, data theft, espionage, or the installation of ransomware.” reported SecurityBridge. “To demonstrate the potential impact of this vulnerability, we have created the attached Demo based on our own research and tooling:”

SecurityBridge experts warn that although not yet widespread, the flaw is already being abused. Unpatched SAP systems are exposed, and exploits are easy to craft by reverse-engineering the ABAP patch.

“The attacker needs only low-level credentials on the SAP system (any valid user account with permissions to call the vulnerable RFC module and the specific S_DMIS authorization with activity 02), and no user interaction is required.” concludes SecurityBridge.

“The attack complexity is low and can be performed over the network, which is why the CVSS score is so high (9.9). In summary, a malicious insider or a threat actor who has gained basic user access (through phishing, for example) could leverage this flaw to escalate into full control of the SAP environment. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SAP S/4HANA)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews



The Roku Sports interface now shows content you can watch on YouTube TV. The new feature, which is rolling out to all Roku devices in the U.S. starting today, will make it easier for fans to find games from YouTube TV, including all the NFL games that come with NFL Sunday Ticket.

Adding YouTube TV pushes Roku’s Sports section pretty far. The section already includes a bunch of other partners like DAZN Live Sports, FOX One, Frndly TV, Spectrum TV, and Xfinity Stream. The whole point is to give sports fans a central hub to find their favorite games, highlights, and scores from all the top leagues.

According to Joe Franzetta, Roku Media’s Head of Sports, the company’s main goal is to make “game time effortless for our users. Partnering with YouTube TV is a major step in delivering a comprehensive fan-centered experience that simplifies sports discovery and puts live action front and center for millions of fans.”

Roku also reported that YouTube TV will be available in other content discovery areas on the platform in the future. This means you’ll be able to find YouTube TV content in other sections that Rokue has, so you don’t miss out on anything important.

YouTube TV is a great app when it comes to live TV, but since the service added the NFL Sunday Ticket, it’s become a massive player in sports broadcasting. It’s also got some pretty sweet features for sports fans, like multiview, which lets you watch up to four games at once. It also has the ability to catch up on key plays, so you don’t have to worry if you’re running a little late. This integration will let YouTube TV subscribers make the most of their subscription by making it easy to find and jump into games.

You can still go straight to the YouTube TV app and look for your sports content there, since nothing will be changing on the app itself. The difference is that now you don’t need to look through the app to find its content, which makes it easier to find what you want since Roku’s sports interface saves a lot of time. I use it during the Super Bowl and on many Sundays. This is easier than trying to keep up with which company owns the right to broadcast the game I want to see.

Roku does offer a lot of content for free, but this does not mean the content shown on YouTube TV will be free. While you only need a Roku TV to get to the sports section, you still need a subscription to watch the content from YouTube TV. You also need the NFL Sunday Ticket for the NFL games included in the pass. It is just like the content shown by other broadcasters that is displayed in the Roku Sports section. So you’ll still need to pay the $85 month-to-month price, unless you took advantage of a promotion.

Source: Roku



Source link