logo

Critical Vulnerability in SAP NetWeaver Visual Composer

ID: 8356c81e-67b9-5265-8701-cc899d103221

STIX ID: report--8356c81e-67b9-5265-8701-cc899d103221

Feed Name: Kudelski Security

Threat Score
88/100

Date Published: 2025-04-25

Date Updated: 2026-07-22

...
...

ReliaQuest confirmed active exploitation of CVE-2025-31324 — an unrestricted file upload vulnerability in SAP NetWeaver Visual Composer’s /developmentserver/metadatauploader endpoint allowing unauthenticated upload of JSP webshells that are written to a publicly served path and used for remote code execution; attackers have leveraged this to deploy Brute Ratel C2 and employ advanced evasion (Heaven’s Gate).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.