SAP Fixes Critical Vulnerability After Evidence of Exploitation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-9844 | SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of Visual Composer deserializes a malicious object that may cause legitimate users accessing a service, either by crashing or flooding the service. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2025-31324 | Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer CVE-2025-31324 is a critical (CVSS 9.8) unrestricted file upload flaw (CWE-434) in the Visual Composer Metadata Uploader component of SAP NetWeaver, which lacks proper authorization. An unauthenticated attacker can send crafted upload requests over the network to the Metadata Uploader endpoint and plant malicious executable binaries, such as webshells, on the host. Executing the uploaded files yields remote code execution with full impact on confidentiality, integrity, and availability, enabling system compromise, lateral movement, and ransomware deployment. Any organization running the affected SAP NetWeaver component is at risk, with the greatest exposure for instances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-04-29, a public PoC exists, and researchers and media report active attacks, including by Chinese-linked actors deploying Golang-based implants on Linux systems and known ransomware use, often chained with CVE-2025-42999. Do: Apply SAP's patch for CVE-2025-31324 (released in the April 2025 security updates) and follow the vendor mitigation instructions per CISA KEV/BOD 22-01 requirements. As interim mitigation, restrict or disable the Visual Composer Metadata Uploader endpoint and ensure it is not reachable from the internet; also patch the related CVE-2025-42999 since the flaws are being chained. Check affected hosts for uploaded webshells, Golang-based implants, and signs of ransomware activity. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of enterprise deployments worldwide, with several thousand instances directly internet-exposed |
Full article453 words · extracted from infosecurity-magazine.com · click to collapse
German software company SAP has finally disclosed and fixed a highly critical vulnerability in the NetWeaver Visual Composer development server after evidence of exploitation in the wild.
NetWeaver Visual Composer is SAP’s web-based modelling tool that allows business process experts and developers to build business application components without requiring manual coding.
The vulnerability, tracked as CVE-2025-31324, is an unauthenticated file upload vulnerability in the Metadata Uploader component of the SAP NetWeaver Visual Composer Framework version 7.50.
When exploited, the vulnerability allows an unauthenticated attacker to upload potentially malicious executable binaries that could severely harm the host system.
“This could significantly affect the confidentiality, integrity and availability of the targeted system,” the CVE.org page for CVE-2025-31324 noted.
The vulnerability has been allocated the highest severity score by SAP, 10.0 (CVSS v3.1).
The German software provider has also released a fix, published in an emergency security update that is only accessible to SAP customers.
Customers have been urged to apply the new versions as soon as possible.
Evidence of Exploitation
The vulnerability was detected by ReliaQuest in April 2025 while investigating multiple customer incidents affecting the technology integration platform SAP NetWeaver, which involved unauthorized file uploads and the execution of malicious files.
In an April 22 article sharing findings from its investigation, ReliaQuest said it initially discovered that attackers had uploaded “JSP webshells” into publicly accessible directories, a move reminiscent of a remote file inclusion (RFI) vulnerability.
Several affected systems were already running the latest SAP service pack and had applied patches made available in SAP's regular monthly update, released on April 8. This indicated that owners of the affected systems were targeted by a zero-day exploit.
“However, SAP later confirmed it as an unrestricted file upload vulnerability, allowing attackers to upload malicious files directly to the system without authorization,” reads the ReliaQuest report.
ReliaQuest added that the exploitation is likely tied to either a previously disclosed vulnerability like CVE-2017-9844 or an unreported remote file inclusion (RFI) issue. Additionally, attackers employed tools like Brute Ratel and Heaven’s Gate for execution and evasion.
After being contacted by ReliaQuest, SAP, which itself is a CVE Numbering Authority (CNA), publicly reported the vulnerability on April 24 and released a fix.
According to ReliaQuest, SAP's solutions are likely an attractive target for threat actors for two key reasons.
“First, they are often used by government agencies, meaning that successful compromise of SAP vulnerabilities is likely to facilitate access to government-related networks and information. Second, as SAP solutions are often deployed on-premises, security measures for these systems are left to users; updates and patches that are not applied promptly are likely to expose these systems to greater risk of compromise,” the ReliaQuest researchers wrote.
Photo credits: Kittyfly/T. Schneider/Shutterstock
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/sap-fixes-critical-vulnerability/