Critical SAP S/4HANA Vulnerability Actively Exploited, Allowing Full System Takeover
A security vulnerability in SAP S/4HANA, identified as CVE-2025-42957, is currently being exploited by attackers. This vulnerability has been assigned a CVSS score of 9.9 out of 10, indicating its severity. It allows a user with low privileges to execute…
A security vulnerability in SAP S/4HANA, identified as CVE-2025-42957, is currently being exploited by attackers. This vulnerability has been assigned a CVSS score of 9.9 out of 10, indicating its severity. It allows a user with low privileges to execute code injection and potentially gain complete control of an SAP system.
CVE Identifier CVSS Score Affected Releases
CVE-2025-42957 9.9 All SAP S/4HANA releases (On-Premise and Private Cloud)
SecurityBridge’s Threat Research Labs initially discovered the flaw during routine security testing and reported it to SAP on June 27, 2025. SAP subsequently issued a patch on August 11, 2025, as part of its August Patch Day. However, the vulnerability is already being exploited in real-world scenarios, making it imperative for organizations to apply the patch immediately.
Exploitation requires a valid SAP user account with access to a vulnerable RFC module and the S_DMIS authorization object with activity 02. No additional user interaction is necessary. Once exploited, an attacker can:
A security vulnerability in SAP S/4HANA, identified as CVE-2025-42957, is currently being exploited by attackers.
Execute arbitrary ABAP code on the SAP application layer Read, modify, or delete data in the SAP database Create new SAP users with full administrative rights (SAP_ALL) Download password hashes for all SAP accounts Alter or disable critical business processes
The attack's simplicity and network-based nature pose a significant threat. Attackers could escalate privileges from basic user credentials obtained through phishing or insider access, leading to potential tampering with financial records, data theft, or ransomware deployment.
The SecurityBridge platform already detects exploitation attempts of CVE-2025-42957
To mitigate the risk, SAP customers are advised to:
Apply SAP Security Notes 3627998 and 3633838 without delay. Review and restrict the usage of the S_DMIS authorization object and limit RFC calls. Monitor system logs for unusual RFC requests or new administrative accounts. Enforce network segmentation and maintain updated backups. Consider deploying SAP UCON to enhance access controls.
Organizations using the SecurityBridge platform can detect and block exploitation attempts for CVE-2025-42957, allowing visibility into suspicious activities.
This incident underscores the importance of timely patching and monitoring within SAP environments. Enterprises should prioritize rapid deployment of updates and bolster their SAP security measures to prevent fraud, data loss, or operational disruption.
Based on reporting by GBHackers.
