CVE-2025-42967

CRITICAL

SAP S/4HANA and SCM Characteristic Propagation - User-Level Report Code Execution

Title source: manual
STIX 2.1

Description

SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 9.9
EPSS 0.0209
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (13)
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 103
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 104
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 106
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 107
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 108
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 701
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 702
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 712
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) 714
SAP_SE/SAP S/4HANA and SAP SCM (Characteristic Propagation) S4CORE 102
... and 3 more
Published Jul 08, 2025
Tracked Since Feb 18, 2026