Tech

SAP patches recently exploited zero-day in wake of NetWeaver server attacks

Share
Share


  • SAP fixed CVE-2025-42999, a 9.1/10 vulnerability in NetWeaver
  • This one was chained with CVE-2025-31324, which was fixed in April
  • Fortune 500 companies are apparently at risk

SAP has patched a critical-severity zero-day vulnerability in NetWeaver server that was being chained in attacks targeting some of the world’s biggest enterprises.

The vulnerability is tracked as CVE-2025-42999, and carries a severity score of 9.1/10 (critical). On NVD, it was said that SAP NetWeaver Visual Composer Metadata Uploader is “vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.”

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Google Messages is finally getting a mentions feature for chats – here’s how it works
Tech

Google Messages is finally getting a mentions feature for chats – here’s how it works

Google Messages is finally getting a mentions features, similar to the one...

Can generative AI replace humans in qualitative research studies?
Tech

Can generative AI replace humans in qualitative research studies?

CMU research shows that replacing humans with LLMs has limitations and presents...