Critical vulnerability in SAP NetWeaver enables malicious file uploads
ID: 6f0744a0-6a01-5dca-ab65-c8c5b755f023
STIX ID: report--6f0744a0-6a01-5dca-ab65-c8c5b755f023
Feed Name: Red Canary
Threat Score
This advisory documents exploitation of SAP CVE-2025-31324, recommends log hunting for requests to /developmentserver/metadatauploader, and instructs searching J2EE directories for unexpected JSP web shells. It enumerates IOCs including IPs, domains, URLs (notably links to config.sh and xmrig-related scripts), and malicious filenames to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
