CVE-2025-42967: SAP SE SAP s/4hana And SAP Scm Characteristic Propagation
Critical severity, CVSS 9.9. EPSS: 1% chance of exploitation in the next 30 days.
SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application.
Affected products
- SAP SE SAP s/4hana And SAP Scm Characteristic Propagation: version 714 only; version S4CORE 102 only; version 103 only; version 104 only; version S4COREOP 105 only; version 106 only; …
Published 2025-07-08. Last modified 2026-06-17.