logo

SAP NetWeaver zero-day allegedly exploited by an initial access broker

ID: 2037bb8c-b642-5616-ab4e-5e037b0de938

STIX ID: report--2037bb8c-b642-5616-ab4e-5e037b0de938

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-04-25

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Critical zero-day (CVE-2025-31324, CVSS 10.0) in SAP NetWeaver Visual Composer Metadata Uploader is being actively exploited to upload JSP webshells to j2ee/cluster/apps/... allowing remote command execution and full system compromise; ReliaQuest documented attacks, identified webshell names/paths and advanced tooling (Brute Ratel, Heaven’s Gate), and SAP released an April 2025 patch—organizations should apply the fixes and monitor for the indicated IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.