Red Hot Cyber
Cybersecurity, Cybercrime News and Vulnerability Analysis
UtiliaCS 970x120
9.9 out of 10! All SAP S/4HANA systems at risk: Patch now!

9.9 out of 10! All SAP S/4HANA systems at risk: Patch now!

8 September 2025 09:49

A critical vulnerability, CVE-2025-42957, has been identified in SAP S/4HANA, which has received a CVSS score of 9.9. The flaw allows a minimally privileged user to perform code injection and effectively take control of the entire system. It was discovered by the SecurityBridge Threat Research Labs team, which also confirmed its exploitation in real-world attacks.

The vulnerability affects all versions of S/4HANA, including Private Cloud and On-Premise. To successfully exploit it, an attacker only needs a low-privileged account, then gains the privileges to execute operating system-level commands, create SAP superusers with SAP_ALL privileges, modify database data and business processes, and steal password hashes.

Therefore, the attack can lead to data theft, financial fraud, espionage, or the installation of ransomware.

SAP released the patches on August 12, 2025, as part of its monthly “Patch Day.” To fix the vulnerability, you must install the updates from note #3627998 and, if you use SLT/DMIS, also from #3633838.

Experts strongly recommend updating immediately, as opening ABAP code facilitates the creation of exploits based on the published patch.

In addition to installing the updates, SAP administrators are advised to restrict RFC usage via SAP UCON, verify access to the S_DMIS authorization object, monitor suspicious RFC calls and new administrators, and ensure network segmentation, backups, and dedicated monitoring are in place.

SecurityBridge emphasizes that attempts have already been recorded exploit the vulnerability, so systems that remain unpatched are truly at risk.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

1744358477148 300x300
Bajram Zeqiri is an expert in cybersecurity, cyber threat intelligence, and digital forensics with over twenty years of experience, combining technical expertise and strategic vision to build cyber resilience for SMEs. Founder of ParagonSec and a technical contributor for Red Hot Cyber, he works in the delivery and design of various cyber services, including SOC, MDR, Incident Response, Security Architecture, Engineering, and Operations. He helps SMEs transform cybersecurity from a cost center into a strategic business enabler.
Areas of Expertise: Cyber threat intelligence, Incident response, Digital forensics, Malware analysis, Security architecture, SOC/MDR operations, OSINT research