Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    What is MicroSD Express? Everything You Need To Know

    June 8, 2025

    5 to avoid pressure washing mistakes

    June 8, 2025

    Spain vs Portugal Live Stream: How to see the Rashtra League Final 2025 from anywhere and for free

    June 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»SAP Patch Second Zero-Day Dosha was exploited in recent attacks
    Security

    SAP Patch Second Zero-Day Dosha was exploited in recent attacks

    PineapplesUpdateBy PineapplesUpdateMay 14, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    SAP Patch Second Zero-Day Dosha was exploited in recent attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SAP Patch Second Zero-Day Dosha was exploited in recent attacks

    SAP has issued patches to exploit each other in recent attacks targeting the SAP Netwever server as zero-day.

    The company issued security updates for this security defect (Cve-2025-42999) On Monday, May 12, saying that it has been tracked as another informal file upload defect ( Cve-2025-31324) Sap netweaver visible in music composer who was fixed in April.

    A SAP spokesperson told Blapping Copper, “SAP is aware of and SAP is addressing the weaknesses in the Natawver Visual Musicians.” “We ask all customers to save these patch to use SAP Netwever. Security notes can be found here: 3594142 And 3604119,

    Reconsideration First discovered The exploiting attacks of CVE-2025-31324 as a zero-day in April reported that the actor of danger was uploading JSP web shells in public directions and after dissolving customers’ systems through unauthorized file uploads on SAP Netwever. The hacked examples were fully patched, indicating that the attackers used zero-day exploitation.

    This malicious activity was also confirmed by cyber security firms Watchtower and also OpasisWho also saw the attackers uploading web shell backdoor on unexpected examples revealed online to the attackers. Vedre Labs of Forescout connected some of these attacks to a Chinese threat actor, it tracks as Chaya_004.

    Onyphe CTO Patriss Affrett told Bleepingcomputer at the end of April that “20 Fortune 500/Global 500 companies are somewhat unsafe, and many of them are compromising,” saying that 1,284 weak examples were exposed at that time, 474 had already compromised.

    Shadowseerver Foundation is now More than 2040 SAP Netwever server tracking Unsecured to exposed and attacks on the Internet.

    Weak sap netweaver server exposed online
    Weak SAP Natway Server Online (Shadowserver Foundation) exposed

    New defects were also exploited in zero-day attacks

    While SAP did not confirm that the CVE-2025-42999 was exploited in the wild, Onapsis Cto Juan Pablo Perez-Etchegoyen told Bleepingcomputer that the threat actors were chasing both weaknesses in the attacks since January.

    “The attacks we saw during March 2025 (which started in January 2025 as it proved to be basic) is actually misusing the two, deficiency of authentication (CVE-2025-31324) as well as Asurakshi D-Serialization (CVE-2015-429999),” Perez-EtcheGegoyen.

    “This combination allowed the attackers to execute the command in a remote manner and on the system without any kind of privileges. This residual risk is basically a D-Si-Serialization vulnerability by users with the role of visuals on the SAP target system.”

    SAP admins are advised to immediately patch their Netwever institute and consider disabled of visual composer service if possible, as well as restrict access to metadata uploader services and monitor the suspected activity on their server.

    Ever since the attacks started, Sisa is couple Cve-2025-31324 blame Known exploitative weaknesses catalogOrdering federal agencies to secure their system by 20 May, as is mandatory Binding Operational Directive (BOD) 22-01,

    “These types of weaknesses are frequent attack vectors for malicious cyber actors and pose significant risks for federal enterprises,” Sisa warned.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    attacks Dosha exploited patch SAP zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe shortage of student loans has doubled. If you are falling behind, how to go back to the track
    Next Article Nissan is shutting down 20,000 workers in the next two years
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    Security

    Supply series attacks Glustac NPM package with 960K weekly download

    June 7, 2025
    Security

    Exploitation of Critical Round Cube webmail as hacker taking intly

    June 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025594 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025536 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025465 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Meta delay entrusts ‘Bhamoth’ AI model, Openi and Google more than one more head start

    May 16, 20250 Views

    The OURA ring found a new rival with just one titanium design and 24/7 biometric tracking – no membership is required

    May 16, 20250 Views

    Filecoin, Lockheed Martin Test IPFS in space

    May 16, 20250 Views
    Our Picks

    What is MicroSD Express? Everything You Need To Know

    June 8, 2025

    5 to avoid pressure washing mistakes

    June 8, 2025

    Spain vs Portugal Live Stream: How to see the Rashtra League Final 2025 from anywhere and for free

    June 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.