Remote Code Execution Vulnerability in SAP S/4HANA Cloud Products
CVE-2025-43010
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-43010?
An authenticated attacker with standard authorization in SAP S/4HANA Cloud Private Edition can exploit a vulnerability within the SCM Master Data Layer. This flaw stems from a lack of adequate input validation and the absence of proper authorization checks. By executing a specific function module remotely, the attacker can manipulate and replace arbitrary ABAP programs, including critical SAP standard programs. While the confidentiality of the application remains largely intact, both integrity and availability are significantly compromised, posing serious risks to the operational functionality of affected systems.
Affected Version(s)
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) S4CORE 102
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) 103
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) 104