More

    SAP patches recently exploited zero-day in wake of NetWeaver server attacks




    • SAP fixed CVE-2025-42999, a 9.1/10 vulnerability in NetWeaver
    • This one was chained with CVE-2025-31324, which was fixed in April
    • Fortune 500 companies are apparently at risk

    SAP has patched a critical-severity zero-day vulnerability in NetWeaver server that was being chained in attacks targeting some of the world’s biggest enterprises.

    The vulnerability is tracked as CVE-2025-42999, and carries a severity score of 9.1/10 (critical). On NVD, it was said that SAP NetWeaver Visual Composer Metadata Uploader is “vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.”

    https://cdn.mos.cms.futurecdn.net/KrzT5MkZ7pQERcvimKN9ve.png



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img