Remote Code Execution Vulnerability in SAP Solution Manager
CVE-2025-42880

9.9CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 December 2025

What is CVE-2025-42880?

A vulnerability in SAP Solution Manager arises from inadequate input sanitation, enabling an authenticated attacker to inject harmful code through a remote-enabled function module. This flaw compromises the system's confidentiality, integrity, and availability, potentially allowing the attacker full control over the affected systems.

Affected Version(s)

SAP Solution Manager ST 720

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42880 : Remote Code Execution Vulnerability in SAP Solution Manager