logo

Critical vulnerability in SAP NetWeaver enables malicious file uploads

ID: 6f0744a0-6a01-5dca-ab65-c8c5b755f023

STIX ID: report--6f0744a0-6a01-5dca-ab65-c8c5b755f023

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2025-04-30

Date Updated: 2026-04-29

Author: The Red Canary Team

...
...

This advisory documents exploitation of SAP CVE-2025-31324, recommends log hunting for requests to /developmentserver/metadatauploader, and instructs searching J2EE directories for unexpected JSP web shells. It enumerates IOCs including IPs, domains, URLs (notably links to config.sh and xmrig-related scripts), and malicious filenames to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.