NCERT Issues Red Alert on Critical SAP NetWeaver Flaws

Pakistan’s National Computer Emergency Response Team (NCERT) has issued a red alert, warning organisations of serious security risks due to multiple zero-day vulnerabilities discovered in SAP NetWeaver. These flaws could allow hackers to take full control of enterprise servers without user interaction.

NCERT Issues Red Alert on Critical SAP NetWeaver Flaws

The most dangerous vulnerability, CVE-2025-42944, has been given the maximum CVSS score of 10.0. It affects the RMI-P4 module of SAP NetWeaver ServerCore 7.50. This flaw also allows attackers to remotely execute operating system commands without authentication.

Two other vulnerabilities have also been highlighted:

  • CVE-2025-42922 (CVSS 9.9): Enables insecure file uploads.
  • CVE-2025-42958 (CVSS 9.1): Allows authentication bypass.

Both flaws could be used to escalate privileges, steal sensitive company data, and deploy malware.

“These vulnerabilities pose a severe risk of complete enterprise system takeover. Organizations must patch immediately,” the advisory warned.

See Also: NCERT Issues Grave Warning! One Email Misstep Could Cost Millions – Here’s how to Save Yourself!

Global Risk to Enterprises

SAP NetWeaver is widely used across industries such as banking, telecom, government, and manufacturing. If exploited, these flaws could lead to:

  • Remote code execution.
  • Full server compromise.
  • Malware deployment.
  • Unauthorized privileged access.
  • Large-scale data theft and manipulation.

Urgent Action Required

National CERT has advised all organizations running SAP NetWeaver to act immediately:

  1. Install security patches released by SAP on September 9, 2025 (Notes 3643501, 3643865, 3642961).
  2. Restrict network access to exposed RMI-P4 and Deploy Web Service modules.
  3. Review system configurations and enforce network segmentation.
  4. Monitor for suspicious file uploads and unusual command executions.

As temporary mitigation, CERT suggested firewall restrictions, limiting access only to trusted accounts, and disabling unnecessary upload features.

Threat Monitoring and Response

Organizations have also been told to strengthen their monitoring systems. CERT recommends:

  • Tracking system command executions and authentication logs.
  • Watching for abnormal traffic patterns.
  • Validating backups.
  • Scanning for compromise indicators.
  • Rotating privileged credentials if any breach is suspected.

Bottom Line

SAP systems are critical to global enterprise IT infrastructure. National CERT has also made it clear that delays in patching could expose organizations to ransomware, cyberattacks, and massive data breaches. Quick action is essential to prevent potential damage.

See also: NCERT Issues Advisory on “Blue Locker” Ransomware Targeting Pakistan’s Key Institutions

Mobile Phone Taxes Portal

Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.

Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).

Explore NowFollow us on Google News!

Onsa Mustafa

Onsa is a Software Engineer and a tech blogger who focuses on providing the latest information regarding the innovations happening in the IT world. She likes reading, photography, travelling and exploring nature.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
>