‎2025 Apr 27 11:04 PM - edited ‎2025 Apr 27 11:06 PM
Over this past weekend I saw 2 social media posts on a "zero-day" vulnerability. As usual with bad news, it dropped when many people may not be on the office network. I am curious who has seen this news, how they found it, and whether they escalated/responded. Don't post with "we're on X version" or whatever, just if you knew/know.
"SAP has released an out-of-band emergency update to fix a critical zero-day vulnerability (CVE-2025-31324) in NetWeaver Visual Composer — and it’s already being exploited in the wild." [source: https://infosec.exchange/@Efani/114405113950458290 ]
See: SAP Security Note 3594142
‎2025 Apr 28 10:26 AM
‎2025 Apr 28 10:40 AM
as @TammyPowlas noted, it is just about everywhere... I even got messages from non-SAP friends quoting other sources! 😄
‎2025 Apr 29 1:05 PM
And I just learn from you! 😅
Maybe because I'm not in the basis team
‎2025 May 20 1:56 PM
I go an e-mail "A priority 'Very High' SAP Note/KBA has just been released on component EP-VC-INF" (Fr 25.04.2025 14:12)