CVE-2025-42934: SAP SE SAP s/4hana Supplier Invoice

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted Sites' configuration by injecting line feed (LF) characters into application inputs. This vulnerability has a low impact on the application's integrity and no impact on confidentiality or availability.

Affected products

  • SAP SE SAP s/4hana Supplier Invoice: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; …

Published 2025-08-12. Last modified 2026-06-17.