SAP NetWeaver Visual Composer Flaw Under Active Exploitation
ID: fe84f3a9-278b-5491-bade-805b4b10aac2
STIX ID: report--fe84f3a9-278b-5491-bade-805b4b10aac2
Feed Name: Dark Reading
A critical zero-day vulnerability (CVE-2025-31324) in SAP NetWeaver Visual Composer's Metadata Uploader allows unauthenticated attackers to upload arbitrary files to exposed systems, enabling deployment of JSP web shells and full administrative access; security vendors (ReliaQuest, Rapid7, Onapsis) observed active exploitation beginning in late March, Shadowserver found 454 vulnerable internet-facing instances, and attackers have used Brute Ratel and memory-evasion techniques for C2 and persistence — organizations are urged to patch immediately or disable the component and restrict access to the affected endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
