CVE-2025-42957

CRITICAL EXPLOITED

SAP S/4HANA - Authenticated ABAP Code Injection via RFC Function Module

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-42957 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including mrk336.

AI-analyzed exploit summary This repository contains a working proof-of-concept exploit for CVE-2025-42957, demonstrating how an attacker with low-privileged access can inject arbitrary ABAP code into an RFC-enabled function module in SAP S/4HANA to create an admin user and gain full system control.

Description

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

Exploits (1)

nomisec WORKING POC 3 stars
by mrk336 · local
https://github.com/mrk336/CVE-2025-42957-SAP-S-4HANA-Under-Siege

This repository contains a working proof-of-concept exploit for CVE-2025-42957, demonstrating how an attacker with low-privileged access can inject arbitrary ABAP code into an RFC-enabled function module in SAP S/4HANA to create an admin user and gain full system control.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SAP S/4HANA (RFC-enabled function module ZVULN_EXPL)
Auth required
Prerequisites: Low-privileged access to SAP S/4HANA · Ability to call RFC function modules
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References

Scores

CVSS v3 9.9
EPSS 0.0046
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

VulnCheck KEV 2025-09-04
CWE
CWE-94
Status published
Products (7)
SAP_SE/SAP S/4HANA (Private Cloud or On-Premise) 103
SAP_SE/SAP S/4HANA (Private Cloud or On-Premise) 104
SAP_SE/SAP S/4HANA (Private Cloud or On-Premise) 105
SAP_SE/SAP S/4HANA (Private Cloud or On-Premise) 106
SAP_SE/SAP S/4HANA (Private Cloud or On-Premise) 107
SAP_SE/SAP S/4HANA (Private Cloud or On-Premise) 108
SAP_SE/SAP S/4HANA (Private Cloud or On-Premise) S4CORE 102
Published Aug 12, 2025
Tracked Since Feb 18, 2026