SAP NetWeaver zero-day allegedly exploited by an initial access broker
ID: 2037bb8c-b642-5616-ab4e-5e037b0de938
STIX ID: report--2037bb8c-b642-5616-ab4e-5e037b0de938
Feed Name: Security Affairs
Threat Score
Critical zero-day (CVE-2025-31324, CVSS 10.0) in SAP NetWeaver Visual Composer Metadata Uploader is being actively exploited to upload JSP webshells to j2ee/cluster/apps/... allowing remote command execution and full system compromise; ReliaQuest documented attacks, identified webshell names/paths and advanced tooling (Brute Ratel, Heaven’s Gate), and SAP released an April 2025 patch—organizations should apply the fixes and monitor for the indicated IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
