🚨 New critical SAP NetWeaver RCE vulnerability (CVE-2025-31324)
Unauthenticated attackers can upload malicious files via /developmentserver/metadatauploader, leading to full system compromise.
Exploited in the wild with web shells & reverse proxies.
CVSS 10.0 – patch immediately!
unit42.paloaltonetworks.com/…
🚨 Critical SAP NetWeaver vuln (CVE-2025-31324) under active attack. Allows unauthorized uploads & full system takeover.
Patch now, disable "developmentserver," block Visual Composer, and monitor for rogue JSP files. #CyberSecurity#SAP
Attackers are exploiting CVE-2025-31324 (CVSS 10.0) in SAP NetWeaver Visual Composer to gain initial access.
@rapid7#MDR has tracked active exploitation since at least March 27:
- Targets: mainly manufacturing orgs
- Method: unrestricted file upload to deploy webshells
🛡️ Strong threat detection and response is critical — look for unusual process execution by webserver processes to catch exploitation.
SAP customers:
⚡ Confirm if VCFRAMEWORK.SCA is installed
⚡ Patch immediately
⚡ Restrict access to /developmentserver/metadatauploader
⚡ Hunt for rogue .jsp, .java, .class files
Details IOCs: rapid7.com/blog/post/2025/04…
🚨 SAP NetWeaver Zero-Day Under Active Exploitation — Patch Immediately
SAP has released an out-of-band emergency update to fix a critical zero-day vulnerability (CVE-2025-31324) in NetWeaver Visual Composer — and it’s already being exploited in the wild.
The flaw (CVSS 10.0) allows unauthenticated remote attackers to upload malicious files and gain full remote code execution — no login required.
Here’s what’s happening:
- Threat actors are abusing the `/developmentserver/metadatauploader` endpoint
- They're dropping JSP web shells and executing commands directly from browsers
- Post-exploitation activity includes tools like Brute Ratel and MSBuild injection for stealth
- Even fully patched systems were compromised — confirming this was a true zero-day
Both ReliaQuest and watchTowr have confirmed active exploitation, with attackers already moving to establish persistence and lateral movement.
Who’s affected:
- SAP NetWeaver Visual Composer 7.50 environments
- Systems exposed to the internet, especially if Visual Composer is enabled
What you need to do:
- Apply the emergency patch from SAP (released after the April 8 update)
- If you can’t patch immediately:
- Restrict access to the vulnerable endpoint
- Disable Visual Composer if unused
- Forward logs to SIEM and scan for unauthorized servlet uploads
Also included in the emergency update:
- CVE-2025-27429 — Code injection in SAP S/4HANA
- CVE-2025-31330 — Code injection in SAP Landscape Transformation
In a world where zero-days are increasingly exploited within hours of discovery, patching isn’t optional — it’s urgent.
#SAP#NetWeaver#CyberSecurity
Humom must start to work know from 17:30 to 20:00 or 21:00 because the connection to the developmentserver breaks down because whole Freiburg from the provider got limited on the traffic of max 2mbit #palsporch