Remote Code Execution Vulnerability in SAP S/4HANA Cloud Products
CVE-2025-43010

8.3HIGH

What is CVE-2025-43010?

An authenticated attacker with standard authorization in SAP S/4HANA Cloud Private Edition can exploit a vulnerability within the SCM Master Data Layer. This flaw stems from a lack of adequate input validation and the absence of proper authorization checks. By executing a specific function module remotely, the attacker can manipulate and replace arbitrary ABAP programs, including critical SAP standard programs. While the confidentiality of the application remains largely intact, both integrity and availability are significantly compromised, posing serious risks to the operational functionality of affected systems.

Affected Version(s)

SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) S4CORE 102

SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) 103

SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) 104

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.