Tech

SAP patches recently exploited zero-day in wake of NetWeaver server attacks

Share
Share


  • SAP fixed CVE-2025-42999, a 9.1/10 vulnerability in NetWeaver
  • This one was chained with CVE-2025-31324, which was fixed in April
  • Fortune 500 companies are apparently at risk

SAP has patched a critical-severity zero-day vulnerability in NetWeaver server that was being chained in attacks targeting some of the world’s biggest enterprises.

The vulnerability is tracked as CVE-2025-42999, and carries a severity score of 9.1/10 (critical). On NVD, it was said that SAP NetWeaver Visual Composer Metadata Uploader is “vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.”

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
China’s new 128-core server CPU could be AMD and Intel’s worst nightmare in the data center
Tech

China’s new 128-core server CPU could be AMD and Intel’s worst nightmare in the data center

Hygon’s C86-5G breaks free from AMD Zen, unleashing 128 cores of homegrown...

A new neural network paradigm
Tech

A new neural network paradigm

Comparison between classic Hopfield and IDP Hopfield models. Credit: Science Advances (2025)....

Ransomware drives US health data breaches
Tech

Ransomware drives US health data breaches

Credit: CC0 Public Domain A new study led by researchers from Michigan...

Chinese energy tech exports found to contain hidden comms and radio devices
Tech

Chinese energy tech exports found to contain hidden comms and radio devices

Communication devices have been found in Chinese made solar inverters These have...