Join our Newsletter — 33% off our NHI Course

SAP code injection in S/4HANA: are low-privilege controls enough?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: CVE-2025-42957 is a critical SAP S/4HANA code injection flaw that lets a low-privilege user reach vulnerable RFC paths and take full control, with SAP fixing it in August 2025 and Pathlock reporting exploitation attempts in telemetry. The incident shows that privilege level alone is not a safety signal when network-reachable execution paths remain open.

Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “Patch Now |CVE‑2025‑42957| Critical SAP S/4HANA Code Injection Vulnerability”.

Key questions

Q: What breaks when SAP RFC modules are reachable by low-privilege users?

A: A low-privilege account can become a code execution path when a remote-enabled function module accepts injected ABAP.

Q: Why do SAP code injection flaws create such large identity risk?

A: They let an ordinary user leverage application trust to cross into privileged execution without first compromising an admin account.

Q: What do security teams get wrong about patching SAP vulnerabilities?

A: They often treat patching as an infrastructure task instead of a control-state change.

Practitioner guidance

  • Patch the affected SAP notes immediately Apply Note 3627998 for S/4HANA and, where relevant, Note 3633838 for SLT or DMIS.
  • Reduce RFC exposure with allowlists Use UCON and RFC allowlists to keep only necessary remote-enabled function modules reachable.
  • Harden RFC callback security Review callback behaviour in SM59 and enforce a secure RFC callback security method so callback abuse does not remain a viable escalation route.

Bottom line: CVE-2025-42957 shows that low-privilege SAP access can still become full system control when a reachable RFC module accepts injected code.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 20 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Low privilege is not a meaningful safety boundary when execution paths stay open. In SAP environments, the dangerous object is often the reachable function module, not the nominal user role. That distinction matters because the attacker does not need elevated identity if the code path itself can be abused. Practitioners should treat user privilege and execution reachability as separate governance questions, not a single control outcome.

A question worth separating out:

Q: How should SAP security teams respond when RFC exposure meets low-trust identities?

A: They should treat RFC reachability as an identity governance issue, not just an application setting. The practical question is which identities can reach remote-enabled functions, whether callbacks are constrained, and whether those paths can still be abused after patching. That is how exposure becomes measurable.

👉 Read our full editorial: SAP S/4HANA code injection exposes the limits of low-privilege trust


This post was modified 20 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.