Forum Discussion
CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver...
CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver Exploited in the Wild
On April 22, ReliaQuest published details of their investigation of exploit activity in SAP NetWeaver servers. ReliaQuest reported their findings to SAP and on April 24, SAP disclosed CVE-2025-31324, a critical missing authorization check vulnerability with the highest severity CVSS score of 10.0.
CVE-2025-31324 is an unauthenticated file upload vulnerability affecting the Metadata Uploader component of SAP NetWeaver Visual Composer. Successful exploitation of this vulnerability could allow an unauthenticated attacker to upload malicious files which can be used by an attacker to achieve code execution. The flaw is the result of missing authorization checks to the “/developmentserver/metadatauploader” endpoint. According to ReliaQuest, this vulnerability has been exploited in the wild as a zero-day by threat actors who have abused the flaw to upload malicious web shells to affected hosts. These webshells were used to deploy malware and establish communications with command and control (C2) servers.
For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.