See the Complete Picture.
Published loading...Updated

SAP patches recently exploited zero-day in wake of NetWeaver server attacks

  • SAP released patches in April and May 2025 to fix two zero-day vulnerabilities, CVE-2025-31324 and CVE-2025-42999, exploited in NetWeaver server attacks.
  • These vulnerabilities, discovered amid ongoing investigations, were chained in attacks starting January 2025 and targeted numerous enterprises including Fortune 500 companies.
  • Attackers used unauthenticated file uploads to deploy web shells and remote code execution tools, compromising over 470 SAP NetWeaver instances exposed online worldwide.
  • Patrice Auffret, CTO of Onyphe, revealed that approximately twenty major corporations listed in the Fortune 500 or Global 500 were at risk, with a significant number already affected by security breaches.
  • SAP and security firms urge administrators to patch systems immediately, restrict access, and monitor for threats, while agencies like CISA enforce compliance due to risks of espionage and data exfiltration.
Insights by Ground AI
Does this summary seem wrong?

19 Articles

All
Left
Center
3
Right
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

slashdot.org broke the news in on Sunday, May 11, 2025.
Sources are mostly out of (0)

Similar News Topics