Threat Brief: CVE-2025-31324 (Updated June 25)
ID: 74132f91-e4d2-50d2-bb5e-247b996175a4
STIX ID: report--74132f91-e4d2-50d2-bb5e-247b996175a4
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 describes CVE-2025-31324, an unauthenticated arbitrary-file-upload vulnerability in SAP NetWeaver Visual Composer that has been actively exploited in the wild to deploy JSP web shells, reverse shells (including a GOREVERSE ELF), reverse SSH SOCKS proxies, and Cobalt Strike beacons; the brief provides observed commands, network and file indicators (IPs, domains, SHA256 hashes), remediation recommendations, and product protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
