CRLF Injection Vulnerability in SAP S/4HANA Supplier Invoice
CVE-2025-42934

4.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
12 August 2025

What is CVE-2025-42934?

The SAP S/4HANA Supplier Invoice is susceptible to a CRLF injection vulnerability. This flaw allows attackers with user-level privileges to bypass established allowlists, enabling the injection of untrusted sites into the 'Trusted Sites' configuration. By exploiting this vulnerability, malicious actors can manipulate application inputs, potentially compromising system integrity. While this issue exhibits a limited impact on application functionality and does not threaten confidentiality or availability, it highlights the importance of maintaining stringent security measures to safeguard against this type of injection attack.

Affected Version(s)

SAP S/4HANA (Supplier invoice) S4CORE 102

SAP S/4HANA (Supplier invoice) 103

SAP S/4HANA (Supplier invoice) 104

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.