SAP Landscape Transformation Arbitrary Code Injection Vulnerability via RFC

Vulnerability

A vulnerability in SAP Landscape Transformation allows an attacker with admin privileges to inject arbitrary ABAP code or operating system commands into the system, bypassing crucial authorization checks. This flaw, exposed through a function module via Remote Function Call (RFC), effectively acts as a backdoor, potentially leading to a complete system compromise and undermining the system's confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability could result in a full system compromise, allowing unauthorized access and control over the affected system.

Remediation

Users are advised to consult the SAP Security Notes for guidance on applying necessary patches. SAP Security Notes can be accessed through the SAP for Me platform, specifically on the SAP Security Patch Day.

Added: Jan 13, 2026, 2:37 AM
Updated: Jan 13, 2026, 2:37 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
4.4
remediation
8.3
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.