CVE-2025-42950

Published Aug 12, 2025

Last updated 4 months ago

Overview

Description
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Source
cna@sap.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-94

Social media

Hype score
Not currently trending
  1. ⚠️ Threat Actors are exploiting a Code Injection flaw in SAP S/4HANA (Private Cloud & On-Prem) 🚨 CVE-2025-42957 (CVSS 9.9) — Active Exploit 🔒 Patch now → SAP Note 3627998 📌 Also apply Note 3633838 (CVE-2025-42950, SLT/DMIS) 🛡 Harden configs & monitor f

    @IamTaradutt

    13 Sept 2025

    679 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2025-42950 (CVSS:9.9, CRITICAL) is Awaiting Analysis. SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo..https://t.co/0VvoHEB8pM #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    17 Aug 2025

    23 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. ⚠️Actualización de seguridad de SAP ❗CVE-2025-42957 ❗CVE-2025-42950 ❗CVE-2025-42951 ➡️Más info: https://t.co/jxqwH2t7xx https://t.co/jGRCP6KPvz

    @CERTpy

    13 Aug 2025

    101 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-42950 är en kritisk sårbarhet i SAP Landscape Transformation som möjliggör injektion av godtycklig ABAP-kod, vilket kan leda till fullständig systemkompromiss. Säkerhetsåtgärder är avgörande för att skydda mot denna risk. #säkerhet #cybersäkerhet #CVE

    @Sakerhetsblogg

    12 Aug 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. SAP’s August 2025 Patch Tuesday fixes 15 vulnerabilities in S/4HANA and NetWeaver, including critical code injection flaws CVE-2025-42950 and CVE-2025-42957 enabling remote code execution. #SAPPatches #CodeInjection #Germany https://t.co/MoTNVXkAkX

    @TweetThreatNews

    12 Aug 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-42950 SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the in… https://t.co/oOQfwIhL3z

    @CVEnew

    12 Aug 2025

    369 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-42950: CRITICAL] Beware of SAP Landscape Transformation vulnerability allowing injection of ABAP code by attackers, risking full system compromise and cyber security threat.#cve,CVE-2025-42950,#cybersecurity https://t.co/Dcn9feDQtg https://t.co/mlrHpmfjkj

    @CveFindCom

    12 Aug 2025

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.