Critical SAP S/4HANA flaw CVE-2025-42957 under active exploitation

https://securityaffairs.com/181930/hacking/critical-sap-s-4hana-flaw-cve-2025-42957-under-active-exploitation.html

Experts warn of an actively exploited vulnerability, tracked as CVE-2025-42957 (CVSS score: 9.9), in SAP S/4HANA software. A critical command injection vulnerability, tracked as CVE-2025-42957 (CVSS score of 9.9), in SAP S/4HANA is under active exploitation. An attacker can exploit this flaw to fully compromise SAP systems, altering databases, creating superuser accounts, and stealing password hashes. “SAP […]

9 points · 2 comments · view on lemmy.world

2 Comments

blackfire@lemmy.world · 1 pts · 336d (1 reply)

This sounds pretty brutal with user level access. No mitigation just patch and patch now or boom.

lemmydev2@infosec.pub · 1 pts · 335d

And on a weekend 🥳