Critical, Make-Me-Super-User SAP S/4HANA Bug Being Exploited
A critical SAP S/4HANA vulnerability allows low-privileged users to inject code and seize control; patch released August 11, but attackers actively exploit unpatched systems, SecurityBridge warns.
8 Articles
8 Articles
Critical SAP S/4HANA flaw CVE-2025-42957 under active exploitation
Experts warn of an actively exploited vulnerability, tracked as CVE-2025-42957 (CVSS score: 9.9), in SAP S/4HANA software. A critical command injection vulnerability, tracked as CVE-2025-42957 (CVSS score of 9.9), in SAP S/4HANA is under active exploitation. An attacker can exploit this flaw… Read more → The post Critical SAP S/4HANA flaw CVE-2025-42957 under active exploitation appeared first on IT Security News.
An exploit for the vulnerability has already been observed in the wild. Nitpicker / Shutterstock Last month, SAP released a patch for S/4HANA intended to address the massive vulnerability CVE-2025-42957, which has a CVSS score of 9.9. The recently discovered exploit allows a user with low privileges to gain complete control over an S/4HANA system through code injection in the SAP ABAP programming language. All S/4HANA versions—both in the privat…
Attackers are exploiting critical SAP S/4HANA vulnerability (CVE-2025-42957) - Help Net Security
A critical vulnerability (CVE-2025-42957) in SAP S/4HANA enterprise resource planning software is being exploited by attackers “to a limited extent”, the Dutch National Cyber Security Center (NCSC NL) has warned on Friday. Their alert seems to be based on a report by SecurityBridge’s Threat Research Labs, who professedly verified that the exploit for the flaw is being used in the wild. About CVE-2025-42957 CVE-2025-42957 is a code injection vuln…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium