Critical Vulnerability in SAP NetWeaver Visual Composer
ID: 8356c81e-67b9-5265-8701-cc899d103221
STIX ID: report--8356c81e-67b9-5265-8701-cc899d103221
Feed Name: Kudelski Security
Threat Score
ReliaQuest confirmed active exploitation of CVE-2025-31324 — an unrestricted file upload vulnerability in SAP NetWeaver Visual Composer’s /developmentserver/metadatauploader endpoint allowing unauthenticated upload of JSP webshells that are written to a publicly served path and used for remote code execution; attackers have leveraged this to deploy Brute Ratel C2 and employ advanced evasion (Heaven’s Gate).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
