CVE-2025-42957
CRITICAL EXPLOITEDSAP S/4HANA - Authenticated ABAP Code Injection via RFC Function Module
Title source: llmExploitation Summary
CVE-2025-42957 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including mrk336.
AI-analyzed exploit summary This repository contains a working proof-of-concept exploit for CVE-2025-42957, demonstrating how an attacker with low-privileged access can inject arbitrary ABAP code into an RFC-enabled function module in SAP S/4HANA to create an admin user and gain full system control.
Description
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Exploits (1)
This repository contains a working proof-of-concept exploit for CVE-2025-42957, demonstrating how an attacker with low-privileged access can inject arbitrary ABAP code into an RFC-enabled function module in SAP S/4HANA to create an admin user and gain full system control.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H