Critical SAP S/4HANA Vulnerability Actively Exploited By Hackers

The exploitation requires only a low-privileged account to achieve full compromise.

A newly disclosed critical vulnerability in SAP's flagship enterprise software, S/4HANA, is being actively exploited by cybercriminals, security researchers have warned.

The flaw, tracked as CVE-2025-42957, carries a CVSS score of 9.9 and affects both on-premise and Private Cloud editions of S/4HANA.

It was patched by SAP on Aug. 11 but many organizations have yet to apply the fix, leaving systems exposed.

According to the National Vulnerability Database (NVD), the bug arises from a command injection flaw in a function module exposed via Remote Function Call (RFC).

Exploitation allows attackers with low-level user privileges to inject arbitrary ABAP code, bypassing critical authorization checks.

"This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system," the NVD description of the vulnerability states.

Exploitation In The Wild

SecurityBridge Threat Research Labs, which originally discovered and reported the issue to SAP on June 27, confirmed last week that attackers are already abusing the vulnerability.

Exploitation requires only a low-privileged account to achieve full compromise, the company said.

A successful attack can easily lead to fraud, espionage, data theft, or the installation of ransomware.

"The attacker needs only low-level credentials on the SAP system, and no user interaction is required," SecurityBridge stated.

"The attack complexity is low and can be performed over the network, which is why the CVSS score is so high (9.9)… a malicious insider or a threat actor who has gained basic user access (through phishing, for example) could leverage this flaw to escalate into full control of the SAP environment."

The firm noted that while widespread exploitation has not yet been observed, it has verified real-world abuse of the flaw.

Because SAP's ABAP code is visible, reverse engineering the patch to build exploits is considered relatively easy.

SecurityBridge has also released a demonstration video showing how attackers can use the flaw to execute system commands on SAP servers.

The vulnerability impacts multiple SAP products and versions, including:

S/4HANA (Private Cloud & On-Premise): S4CORE 102-108

Landscape Transformation (DMIS): versions 2011_1_700 through 2020

Business One (SLD): B1_ON_HANA 10.0, SAP-M-BO 10.0

NetWeaver Application Server ABAP (BIC Document): S4COREOP 104-108, SEM-BW 600-748

Pathlock, another cybersecurity vendor, reported that it has detected "outlier activity consistent with exploitation attempts" linked to CVE-2025-42957.

Both Pathlock and SecurityBridge urged administrators to immediately deploy SAP's August 2025 Patch Day updates.

As an additional safeguard, organizations were advised to implement SAP UCON to restrict RFC usage and tighten access to authorization object S_DMIS activity 02.

Given SAP S/4HANA's central role in managing finance, logistics, supply chains, and human resources for global enterprises, a successful exploit could have devastating consequences.

"We must emphasize that detection is no substitute for remediation," SecurityBridge said.

"The primary recommendation is still to apply SAP's patch immediately; monitoring is a complementary measure in case an attacker attempts to exploit before your patch is applied."

This article originally appeared on our sister site Computing.