Vulnerability Details
Basic Information
| Title | SAP Confirms Critical NetWeaver Flaw Amid Suspected Zero-Day Exploitation by Hackers |
|---|---|
| Type | thn |
| Published | 2025-04-25T10:41:00 |
| Last Seen | 2025-04-25T10:54:50 |
| CVSS Score | 10.0 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2017-12637, CVE-2017-9844, CVE-2025-31324 |
|---|---|
| CWE | |
| Bulletin Family | info |
Description
Threat actors are likely exploiting a new vulnerability in SAP NetWeaver to upload JSP web shells with the goal of facilitating unauthorized file uploads and code execution. "The exploitation is likely tied to either a previously…
Impact Assessment
| Base Score | 10.0 |
|---|---|
| Severity | CRITICAL |