CVE-2025-42887: SAP SE SAP Solution Manager

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

Affected products

Published 2025-11-11. Last modified 2026-06-17.