SAP S/4HANA administrators who have not already installed the August 11 critical update may face problems: An exploit for the code injection vulnerability is already being actively exploited.
See also: CISA adds two TP-Link vulnerabilities to KEV List

The vulnerability, CVE-2025-42957 (with a CVSS score of 9.9), allows a low-privileged user to gain complete control of an SAP system via code injection in ABAP . All versions of SAP S/4HANA – both private cloud and on-premises – are vulnerable.
SecurityBridge , which reported Thursday that it discovered the exploit, said that successful exploitation provides access to the operating system and full access to all data in the SAP system. If the update has not yet been installed, it should be installed immediately. “ While there has been no reported widespread exploitation ,” SecurityBridge, based in Germany, said in a blog post Thursday, it has verified actual abuse of the vulnerability.
Reverse engineering the update to create an exploit is relatively easy in the SAP ABAP programming language, SecurityBridge added, as the ABAP code is open for anyone to see. It is not known how many administrators have already installed the update. “ This vulnerability was rated 9.9; [that’s] quite high ,” Juan Pablo Perez-Etchegoyen , CTO of security firm Onapsis, which regularly reports SAP vulnerabilities, said in an interview
While some IT networks may need downtime to install SAP updates, he added, “our expectation is that the majority of organizations should have applied these updates” by now. The exploit could lead to bad business decisions. Because SAP S/4HANA is an enterprise resource management system that runs on the company’s in-memory database, the exploit could be devastating.
See also: Critical vulnerability in Django: Update immediately!

In case CSOs and SAP S/4HANA administrators don't understand the possibilities, SecurityBridge listed a few things a malicious actor exploiting the flaw could do: delete and insert data directly into the SAP database, create SAP users with SAP_ALL, download password hashes, modify business processes.
The complexity of the platform leads to potential vulnerabilities. SAP S/4HANA is no stranger to vulnerabilities. In April, for example, a cross-site request forgery in the Learning Solution module of S/4HANA (CVE-2025-31328). In February, an open redirect vulnerability was found in the Extended Application (XS) Services Advanced of S/4HANA (CVE-2025-24868) that allows an unauthenticated attacker to create a malicious link that redirects an unsuspecting victim to a malicious website.
Eric Mehler, a Germany-based CISO who writes about common security vulnerabilities in S/4HANA, has written that the complexity of the platform can introduce potential security vulnerabilities, often due to misconfiguration or oversights. These issues include maintaining default SAP accounts that still use default passwords and excessive user privileges, allowing unencrypted SAP traffic or traffic with outdated protocols such as TLS 1.0, inadequate traffic monitoring and logging, and insecure ABAP programming practices.
See also: CISA: Warns of critical vulnerability in SunPower devices

“Threat actors are very active in targeting SAP applications,” said Perez-Etchegoyen . Last month, an exploit for a zero-day vulnerability in SAP NetWeaver (CVE-23025-31324, a lack of authentication flaw) was reportedly released by a gang, he noted. “So it’s more important than ever for organizations to integrate SAP security into their IT security landscape” and apply updates as soon as possible.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
