CRLF Injection Vulnerability in SAP S/4HANA Supplier Invoice
CVE-2025-42934
What is CVE-2025-42934?
The SAP S/4HANA Supplier Invoice is susceptible to a CRLF injection vulnerability. This flaw allows attackers with user-level privileges to bypass established allowlists, enabling the injection of untrusted sites into the 'Trusted Sites' configuration. By exploiting this vulnerability, malicious actors can manipulate application inputs, potentially compromising system integrity. While this issue exhibits a limited impact on application functionality and does not threaten confidentiality or availability, it highlights the importance of maintaining stringent security measures to safeguard against this type of injection attack.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP S/4HANA (Supplier invoice) S4CORE 102
SAP S/4HANA (Supplier invoice) 103
SAP S/4HANA (Supplier invoice) 104
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved