- SAP FIXED CVE-2025-42999, a 9.1/10-vulnerability in Netweaver
- This one was tied with CVE-2025-31324 which was attached in April
- Fortune 500 -Companies are apparently in danger
SAP has patched a critical-difficulty zero-day vulnerability in Netweaver server, which was tied in attacks targeting some of the world’s largest companies.
Vulnerability is traced as CVE-2025-42999 and has a severity of 9.1/10 (critical). At NVD it was said that SAP Netweaver Visual Composer Metadata Uploader is “vulnerable when a privileged user can upload non -procedure or malicious content which, when deserialized, can potentially lead to a compromise of confidentiality, integrity and availability of the host system.”
In a statement made to Bleeping computerSAP said it discovered this error when it examined another, also a zero day. This was reported earlier in April this year and is now being tracked as CVE-2025-31324 (10/10-critical). The two deficiencies were reportedly abused in attacks since January 2025.
SAP problems patch
When security researchers first discovered CVE-2025-31324, which was abused, it was said that more than 1,200 SAP cases were in danger of being hijacked. Some researchers claimed that the number of vulnerable final points was somewhat smaller – about 500 cases.
Visual Composer is a development tool that allows users to build web -based business applications without writing code. It is mostly used to create dashboards, forms and interactive reports. On the other hand, the metadata -Uploader is a tool to import external data models (metadata) into the visual composer design environment. This allows developers to connect to external data sources (web services, databases or SAP systems).
Reliaquest, Watchtowr and Onapsis are just some of the companies that observed that the error was exploited in attacks where threat actors dropped web shells on vulnerable servers. However, SAP told the media that it was not aware of any attack that affected customer data or systems.
“Something like 20 Fortune 500/Global 500 -Companies are vulnerable, and many of them are compromised,” Onyphe CTO Patrice said Bleeping computer.
Via Bleeping computer