Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Important SAP S/4hana vulnerability now exploited in attacks
    Security

    Important SAP S/4hana vulnerability now exploited in attacks

    PineapplesUpdateBy PineapplesUpdateSeptember 5, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Important SAP S/4hana vulnerability now exploited in attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Important SAP S/4hana vulnerability now exploited in attacks

    Researchers have warned that an important SAP S/4hana code injection vulnerability is being leveraged to dissolve the server exposed in attacks in the wild.

    Dosual, tracked as Cve-2025-42957The RFC-exposed function module of SAP S/4HANA has an ABAP code injection problem, allowing low-owned authentication users to inject arbitrary code, bypass authority and take it completely to SAP.

    Seller Decide On August 11, 2025, it is a significant rating (CVSS Score: 9.9).

    However, many systems have not implemented the available security updates, and are now being targeted by hackers who have made bugs weapons.

    According to a report by Securitybridge, CVE-2025-42957 is now active, although limited, subjected to exploitation in the wild.

    Securitybridge said it discovered vulnerability and reported responsibly to the SAP on 27 June 2025, and even assisted in the development of a patch.

    However, due to the openness of the affected components and the ability to reverse the engineer, it is trivial for highly efficient, knowledgeable danger actors who detect self -exploitation.

    “While comprehensive exploitation has not yet been reported, the security person has verified the actual misuse of this vulnerability,” Securitybridge reads report,

    “This means that the attackers already know how it is used – to highlight the unpassed SAP system.”

    “In addition, reverse engineering is relatively easy for the patch to create an exploitation, as the ABAP code is open to see for all.”

    The security firm warned that the possible impacts of CVE-2025-42957 Exploitation include data theft, data manipulation, code injections, backward accounts, credential theft, and operating disintegrations through malware, ransomware, or other means.

    Securitybridge made a video that shown how vulnerability can be exploited to run a system command on the SAP server.

    https://www.youtube.com/watch?v=Snsayb7SMM

    SAP Administrators who have not implemented the August 2025 Patch Day update should do so as soon as possible.

    The affected products and versions are:

    • S/4hana (Private Cloud or On-Emination), Version S4Core 102, 103, 104, 105, 106, 107, 108
    • Landscape Transformation (Analysis Forum), DMIS version 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020
    • Business One (SLD), version B1_on_hana 10.0 and SAP-M-BO 10.0
    • Netweaver Application Server ABAP (BIC Documents), Edition S4Coreop 104, 105, 106, 107, 108, SEM-BW 600, 602, 603, 604, 604, 605, 634, 736, 746, 747, 747, 748

    There is a bulletin with more information about recommended tasks Available hereBut only SAP is worth viewing with an account by customers.

    Bleepingcomputer contacted SAP and Securitybridge how to ask how CVE-2025-42957 is being exploited, but we are still waiting for the response.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    attacks exploited important S4hana SAP vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMassiver anstieg bei hackerangrifen auf deutschen bildungssektor
    Next Article Your last chance to disrupt 2025 is today
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Updated to Android 16? You should enable these 2 important security features ASAP – here’s why

    October 19, 2025
    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Security

    American Airlines subsidiary Envoy confirms Oracle data breach attack

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.