External risk intelligence

SAP Supplier Relationship Management Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-42910

The vulnerability exists in SAP Supplier Relationship Management, an enterprise application typically deployed within internal corporate networks. While the application may be accessible over a network, it is not designed to be a public-facing internet edge service, and usage is generally restricted to authenticated internal users or partners, making public internet exposure less common.

Unrestricted File Upload

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in SAP Supplier Relationship Management allows authenticated users to upload malicious files, potentially leading to the execution of malware and significant impacts on confidentiality, integrity, and availability.

  • Uploading malicious files can lead to malware.
  • It affects SAP Supplier Relationship Management technology.
  • Confirm relevance and exposure to SAP systems.

Attack Path

How an attacker could exploit the issue

An attacker with existing access to SAP Supplier Relationship Management could upload a malicious file, such as an executable. If another user downloads and runs this file, it could lead to the execution of malware, potentially compromising the confidentiality, integrity, and availability of the application.

  • Authenticated access required.
  • User downloads and executes uploaded file.
  • Malware execution and application compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in SAP Supplier Relationship Management could allow an authenticated attacker to upload arbitrary files. If a user downloads and executes these files, they might inadvertently host malware, potentially impacting the confidentiality, integrity, and availability of the application.

  • Arbitrary file uploads are at risk.
  • Uploaded files may be downloaded and executed.
  • High impact to application confidentiality, integrity, availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

SAP Supplier Relationship Management instances are likely managed by platform or application teams responsible for enterprise resource planning systems. The first step is to identify all deployed SAP SRM instances, confirm their network reachability and business criticality, and then engage the accountable SAP Basis or application owner to assess exposure and plan remediation.

  • Identify SAP SRM instances and ownership.
  • Verify network reachability and criticality.
  • Plan remediation with SAP Basis owner.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SAP Supplier Relationship Management?

SAP Supplier Relationship Management (SRM) is an enterprise software suite used by organizations to manage interactions with suppliers, handle procurement processes, and streamline the ordering and purchasing lifecycle. It functions as a centralized platform where businesses coordinate supply chain activities and vendor contracts.

What does CWE-434 mean regarding CVE-2025-42910?

CWE-434 refers to an Unrestricted Upload of File with Dangerous Type weakness. In the context of CVE-2025-42910, this means the software does not properly check the format or content of files being uploaded. Because the system fails to validate these inputs, it allows an attacker to place arbitrary files, such as malicious executables, into the application environment.

How is this vulnerability triggered?

The flaw requires an attacker to already have authenticated access to the application to initiate a file upload. It is not a direct server-side execution bug; rather, it relies on a secondary action where a user must download and execute the malicious file uploaded by the attacker. Simply accessing the system without this specific user-driven interaction does not trigger the malware execution path.

How relevant is this CVE to my organization?

According to Halo Surface Signal, this software is typically deployed within internal corporate networks rather than as a public-facing internet edge service. While network access is required, the risk profile is often centered on the internal environment, affecting authenticated users and partners who have authorized entry to the platform.

What should I do if I run this technology?

The first step is to locate all instances of SAP SRM within your environment and identify the teams responsible for their maintenance. Once identified, confirm the network reachability of these systems and coordinate with your SAP Basis or application owners to review the latest security notes provided by the vendor, which contain the necessary guidance for patching and mitigation.

References