Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Anthropic, Google score win by nabbing OpenAI-backed Harvey as a user

May 13, 2025

Adobe Patches Big Batch of Critical-Severity Software Flaws

May 13, 2025

AWS enters into ‘strategic partnership’ with Saudi Arabia-backed Humain

May 13, 2025
Facebook X (Twitter) Instagram
Trending
  • Anthropic, Google score win by nabbing OpenAI-backed Harvey as a user
  • Adobe Patches Big Batch of Critical-Severity Software Flaws
  • AWS enters into ‘strategic partnership’ with Saudi Arabia-backed Humain
  • Zero-Day Attacks Highlight Another Busy Microsoft Patch Tuesday
  • Flash flooding forces evacuation of elementary school in western Maryland
  • US and Saudi Arabia agree to $142bn weapons sale during Trump visit | Donald Trump News
  • Raiffeisen Bank taps Wise Platform to modernise cross-border payments across CEE
  • Trump admin officially rescinds Biden’s AI diffusion rules
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Tuesday, May 13
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » SAP Patches Another Critical NetWeaver Vulnerability
Cybersecurity

SAP Patches Another Critical NetWeaver Vulnerability

adminBy adminMay 13, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 3


Enterprise software maker SAP on Tuesday released 16 new and two updated security notes as part of its May 2025 Security Patch Day. Two of the notes address critical vulnerabilities in NetWeaver.

The most severe is an update to a note released on April 24 to address CVE-2025-31324 (CVSS score of 10/10), a critical-severity bug in NetWeaver’s Visual Composer development server component that has been exploited in the wild since January, for remote code execution (RCE).

Hundreds of NetWeaver servers have been compromised through CVE-2025-31324’s exploitation, and application security firm Onapsis warns that opportunistic attackers are looking to leverage webshells deployed during the initial zero-day attacks.

The company is seeing “significant activity from attackers who are using public information to trigger exploitation and abuse of webshells placed by the original attackers, who have currently gone dark.”

Analysis of the attacks has led to the discovery of another critical defect in NetWeaver’s Visual Composer. Tracked as CVE-2025-42999 (CVSS score of 9.1) and described as an insecure deserialization issue, the vulnerability was resolved with the second critical security note released on SAP’s May 2025 Security Patch Day.

“SAP did a fantastic job responding quickly to new information and turned around an additional patch to enhance protections for the active exploit in the wild,” Onapsis says.

Since the April 2025 security notes were rolled out, SAP also updated two critical notes addressing code injection issues in S/4HANA (CVE-2025-27429) and Landscape Transformation (CVE-2025-31330). Despite the different CVEs, the notes resolve the same flaw.

On Tuesday, SAP released four new and one updated security notes that address high-severity bugs in Supplier Relationship Management, S/4HANA Cloud Private Edition or On Premise, Business Objects Business Intelligence Platform, Landscape Transformation, and PDCE.

Advertisement. Scroll to continue reading.

The software maker also released 11 new security notes that resolve medium-severity vulnerabilities in various products.

SAP customers are advised to apply the security notes as soon as possible, especially given the ongoing exploitation of CVE-2025-31324.

Related: Second Wave of Attacks Hitting SAP NetWeaver After Zero-Day Compromise

Related: SAP Patches Critical Code Injection Vulnerabilities

Related: SAP Patches High-Severity Vulnerabilities in Commerce, NetWeaver

Related: SAP Releases 21 Security Patches



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Adobe Patches Big Batch of Critical-Severity Software Flaws

May 13, 2025

Zero-Day Attacks Highlight Another Busy Microsoft Patch Tuesday

May 13, 2025

Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments

May 13, 2025

Radware Says Recently Disclosed WAF Bypasses Were Patched in 2023

May 13, 2025

Marks & Spencer Says Data Stolen in Ransomware Attack

May 13, 2025

Output Messenger Zero-Day Exploited by Turkish Hackers for Iraq Spying 

May 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Skechers’ Greenbergs Set To Pocket Up To $1.1 Billion From Sale To 3G

May 6, 2025

Skechers founders Robert Greenberg (left) and Michael Greenberg (right) started the brand more than 30…

Trump Organization Admits President Still Controls His Business

May 6, 2025

Forbes Richest Person In Every State 2025

April 30, 2025

These Billionaire Signers Of The Giving Pledge Signers On Why The Philanthropy Group Still Matters

April 29, 2025
Our Picks

Anthropic, Google score win by nabbing OpenAI-backed Harvey as a user

May 13, 2025

Adobe Patches Big Batch of Critical-Severity Software Flaws

May 13, 2025

AWS enters into ‘strategic partnership’ with Saudi Arabia-backed Humain

May 13, 2025

Zero-Day Attacks Highlight Another Busy Microsoft Patch Tuesday

May 13, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

Anthropic, Google score win by nabbing OpenAI-backed Harvey as a user

May 13, 2025

AWS enters into ‘strategic partnership’ with Saudi Arabia-backed Humain

May 13, 2025

Trump admin officially rescinds Biden’s AI diffusion rules

May 13, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.