Arbitrary Code Injection Vulnerability in SAP S/4HANA
CVE-2025-27429

9.9CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 April 2025

Summary

SAP S/4HANA is vulnerable due to a flaw in the function module exposed via Remote Function Call (RFC), allowing authenticated users to inject arbitrary ABAP code. This breach bypasses vital authorization checks, effectively acting as a backdoor to the system. The vulnerability poses significant risks including potential system compromise, undermining the system's confidentiality, integrity, and availability.

Affected Version(s)

SAP S/4HANA (Private Cloud) S4CORE 102

SAP S/4HANA (Private Cloud) 103

SAP S/4HANA (Private Cloud) 104

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.