CVE-2025-42950 Information
Aug 13, 2025
cve
Description
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system bypassing essential authorization checks. This vulnerability effectively functions as a backdoor creating the risk of full system compromise undermining the confidentiality integrity and availability of the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Reference
https://me.sap.com/notes/3633838 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.9
Related CNNVD
CNNVD-202508-989 (Published: 2025-08-12)
Share on: