We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-31330

Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform)



Description

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

Reserved 2025-03-27 | Published 2025-04-08 | Updated 2025-04-10 | Assigner sap


CRITICAL: 9.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

DMIS 2011_1_700
affected

2011_1_710
affected

2011_1_730
affected

2011_1_731
affected

References

me.sap.com/notes/3587115

url.sap/sapsecuritypatchday

cve.org (CVE-2025-31330)

nvd.nist.gov (CVE-2025-31330)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-31330

Support options

Helpdesk Chat, Email, Knowledgebase