CRLF Injection Vulnerability in SAP S/4HANA Supplier Invoice
CVE-2025-42934
4.3MEDIUM
What is CVE-2025-42934?
The SAP S/4HANA Supplier Invoice is susceptible to a CRLF injection vulnerability. This flaw allows attackers with user-level privileges to bypass established allowlists, enabling the injection of untrusted sites into the 'Trusted Sites' configuration. By exploiting this vulnerability, malicious actors can manipulate application inputs, potentially compromising system integrity. While this issue exhibits a limited impact on application functionality and does not threaten confidentiality or availability, it highlights the importance of maintaining stringent security measures to safeguard against this type of injection attack.
Affected Version(s)
SAP S/4HANA (Supplier invoice) S4CORE 102
SAP S/4HANA (Supplier invoice) 103
SAP S/4HANA (Supplier invoice) 104