A critical code injection vulnerability, tracked as CVE-2025-42880, has been identified in SAP Solution Manager. The flaw arises from insufficient input sanitation, allowing authenticated attackers to inject malicious code via remote-enabled function modules. Successful exploitation could grant attackers full control over the affected system, severely impacting confidentiality, integrity, and availability. The vulnerability is remotely exploitable and has been assigned a CVSS score of 9.9, indicating its high severity. SAP has released a final patch to address this issue, emphasizing the risk of full system compromise if left unremediated.
Security researchers and SAP have highlighted the urgency of applying the patch, as exploitation could lead to complete takeover of SAP Solution Manager environments. Organizations using SAP Solution Manager are strongly advised to review their deployments and apply the latest security updates to mitigate the risk. No specific affected product versions have been listed, but the vulnerability is confirmed to be present in the platform. The disclosure underscores the importance of prompt patch management in enterprise SAP environments to prevent potential attacks leveraging this critical flaw.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-42880 was publicly disclosed as a critical SAP Solution Manager vulnerability with a CVSS score of 9.9. The flaw stems from missing input sanitation and could allow an authenticated attacker to inject malicious code through remote-enabled function modules, potentially leading to full system compromise.
SAP addressed CVE-2025-42880, a critical code injection flaw in SAP Solution Manager, in its December 2025 security update. The fix was described as part of SAP's final patch cycle of 2025, and affected organizations were urged to apply it immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvedetails.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.