Join our Newsletter — 33% off our NHI Course

RFC code injection in SAP landscapes: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: SAP’s August 12, 2025 Patch Day delivers 15 new Security Notes and four updates, including three CVSS 9.9 code injection flaws in S/4HANA, Landscape Transformation, and Analytics that can lead to full system compromise through RFC-exposed function modules, according to Pathlock. RFC trust boundaries are now the decisive control point, because low-privilege access can become arbitrary ABAP execution in one step.

Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “SAP Security Patch Tuesday August 2025 -3 Critical RCEs & 15 Notes”.

By the numbers:

  • SAP released 15 new Security Notes and 4 updates in the August 12, 2025 Patch Day.

Key questions

Q: What breaks when SAP RFC modules are reachable by low-privilege users?

A: A low-privilege account can become a code execution path when a remote-enabled function module accepts injected ABAP.

Q: Why do RFC code injection flaws create such a high SAP compromise risk?

A: Because the injected content can execute inside trusted ABAP processing rather than a sandboxed front end.

Q: How can security teams tell whether SAP RFC access is too broad?

A: Look for RFC paths that are reachable by low-privilege identities, transformation modules callable outside their expected business role, and role design that assumes trusted callers.

Practitioner guidance

  • Restrict RFC-exposed function modules Inventory every externally reachable RFC path in S/4HANA, SLT, and analytics components, then remove or lock down modules that do not need broad caller access.
  • Revalidate SAP authorisation concept controls Review SACF rules and custom role mappings so low-privilege users cannot invoke transformation or administrative functions through integration interfaces.
  • Patch the CVSS 9.9 issues first Prioritise CVE-2025-27429, CVE-2025-42950, and CVE-2025-42957 before routine maintenance windows because they enable code injection into core SAP runtime paths.

Bottom line: RFC-exposed SAP functions can turn low-privilege access into arbitrary ABAP execution if the callable boundary is too trusting.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21539
 

RFC trust is the real control plane in SAP estates: These flaws are not just patchable code defects, they expose a governance assumption that RFC callers are already sufficiently trusted. That assumption fails when low-privilege access can reach executable ABAP paths. The implication is that SAP programmes must treat RFC reachability as an authorisation decision, not just an integration detail.

A question worth separating out:

Q: Should organisations patch first or rework SAP RFC authorisation first?

A: Patch first for immediate exposure reduction, but do not stop there. If RFC authorisation remains broad after remediation, the same structural weakness persists and the next flaw can reuse it. The practical answer is to patch urgently while also re-scoping callable RFC functions and reviewing the authorisation concept behind them.

👉 Read our full editorial: SAP patch day exposes RFC code injection risk across core systems


This post was modified 5 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.