We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-27429

Code Injection Vulnerability in SAP S/4HANA (Private Cloud or On-Premise)



Description

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

Reserved 2025-02-25 | Published 2025-04-08 | Updated 2025-04-14 | Assigner sap


CRITICAL: 9.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

S4CORE 102
affected

103
affected

104
affected

105
affected

106
affected

107
affected

108
affected

References

me.sap.com/notes/3581961

url.sap/sapsecuritypatchday

cve.org (CVE-2025-27429)

nvd.nist.gov (CVE-2025-27429)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-27429

Support options

Helpdesk Chat, Email, Knowledgebase