A critical Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2024-56404, has been detected in One Identity Manager, affecting on-premise installations (versions 9.0.x to 9.2.1). It allows unauthorized privilege escalation by manipulating object identifiers. Organizations should apply available hotfixes or upgrade to version 9.3 to mitigate risks and safeguard against exploitation.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered