SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild

A serious command injection vulnerability, tracked as CVE-2025-42957, has surfaced in SAP S/4HANA and is actively exploited. With a CVSS score of 9.9, this flaw allows attackers with user privileges to compromise critical ERP functions, prompting urgent fixes from SAP.

Key Takeaways:

  • SAP S/4HANA faces a critical command injection vulnerability
  • CVE-2025-42957 holds a near-maximum CVSS score of 9.9
  • Attackers can exploit the flaw with basic user privileges
  • SAP addressed this issue in its recent monthly security updates
  • The vulnerability is confirmed to be actively exploited

Description of the Vulnerability

SAP S/4HANA, a leading Enterprise Resource Planning (ERP) software, has been found to contain a command injection flaw identified as CVE-2025-42957. With a CVSS rating of 9.9, the vulnerability represents a high-severity threat, allowing malicious actors to execute unauthorized commands in the system by abusing the function module if they have basic user-level privileges.

Severity and Exploitation

This vulnerability’s severity is underscored not just by its CVSS score but also by reports of active exploitation in the wild. Attackers with standard user credentials can leverage the flaw to gain deeper access, substantially increasing the risk of unauthorized data manipulation or broader network compromise.

Patch and SAP’s Response

SAP addressed this issue through its monthly updates, released last month. The security patch aims to correct the code paths that allowed unauthorized command injection in SAP S/4HANA. Administrators are strongly advised to apply the patch immediately to safeguard vital ERP processes and data from malicious exploitation.

Implications for Enterprises

Given SAP S/4HANA’s status as a mission-critical ERP solution for countless organizations, any vulnerability within its infrastructure poses a significant threat to business operations. Without timely application of the official patch, companies risk compromising sensitive data and critical workflows integral to their day-to-day functions. As attacks escalate, proactive security measures are vital to protect corporate assets and maintain business continuity.

More from World

Iowa House Backs Casino Smoking Ban
by Oskaloosa
18 hours ago
1 min read
House subcommittee votes to end smoking in casinos and ‘level the playing field’
Shapiro's $53B Budget: Wages, Schools, Marijuana
by Laconiadailysun
18 hours ago
1 min read
Gov. Shapiro unveils budget proposal
Route 46 Revamp: Major Upgrades Planned
by Romesentinel
21 hours ago
2 mins read
State officials to host presentation on Route 46 project
Illinois Considers Tax-Free Tips for Workers
by Communitynewspapergroup
21 hours ago
2 mins read
Lawmaker says adopting federal ‘no tax on tips’ would help workers
Streamlined Reporting for Sexual Assault Survivors
by Themercury
21 hours ago
2 mins read
RCPD announces new online resource for sexual assault reporting
Texas Upset: Democrats Shake GOP Hopes
by Denton Record-chronicle
21 hours ago
1 min read
What a Democratic upset that sent ‘shockwaves’ through the Texas GOP could mean for November
North Fork Girls' Winning Streak Stuns League
by Delta County Independent
1 day ago
1 min read
North Fork girls vault into league contention with wins over top teams
Surrey Traveller Site Rejected Over Safety Concerns
by Surrey Live
1 day ago
1 min read
Surrey Gypsy and Traveller site on former green belt rejected amid safety and sustainability concerns
Urgent: Help Find Missing Teen in Stafford
by Starexponent
1 day ago
1 min read
: Davina Chamlagai (VA)
Streamlining Day Care Approvals in California
by The Napa Valley Register
1 day ago
2 mins read
California lawmaker advances bill to speed opening of residential day care centers
Lawmakers Crack Down on "Forever Chemicals
by Starexponent
1 day ago
1 min read
Bill would ban spreading sludge containing PFAS on fields
Challenging Regier's 2025 Liberal Agenda Claims
by Helenair
1 day ago
1 min read
Letter to the editor: Questioning Matt Regier’s claims