SAP security briefs
3 published alerts for SAP products and services.
SAP NetWeaver Deserialization Vulnerability
SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-42999). SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. CISA remediation due date: 2025-06-05. If you need help checking exposure, call (864) 335-9223.
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-31324). SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries. CISA remediation due date: 2025-05-20. If you need help checking exposure, call (864) 335-9223.
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
SAP Customer Relationship Management (CRM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-2380). SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.