CVE-2025-31324: SAP Zero-Day Vulnerability Exploited by Hackers

Hitesh Suthar
Hitesh Suthar

Software Developer

 
May 10, 2025 3 min read

CVE-2025-31324 Threat Overview

Clock Icon 8 min read

Executive Summary

On April 24, 2025, SAP disclosed CVE-2025-31324, a critical vulnerability with a CVSS score of 10.0 affecting SAP NetWeaver's Visual Composer Framework, version 7.50. This vulnerability allows unauthenticated users to upload arbitrary files, leading to potential remote code execution (RCE) and full system compromise by sending specially crafted HTTP requests to the /developmentserver/metadatauploader endpoint.

Attackers have exploited this vulnerability to deploy web shells such as helper.jsp and cache.jsp for persistent access and command execution. For SAP NetWeaver users, it is crucial to refer to official documentation and instructions from SAP for guidance. Palo Alto Networks customers receive protections through the Next-Generation Firewall, Cortex Xpanse, and Cortex XDR.

Details of CVE-2025-31324

CVE-2025-31324 affects the SAP NetWeaver Application Server Java's Visual Composer component (VCFRAMEWORK), which is commonly used by business analysts. The core issue is a missing authorization check in the Metadata Uploader, allowing unauthenticated users to upload files.

Exploitation Process

  1. Unrestricted access: The /developmentserver/metadatauploader endpoint lacks proper authentication.
  2. Malicious file upload: Attackers send crafted HTTP requests containing malicious files.
  3. File system access: The server writes the uploaded file to accessible directories.
  4. Web shell execution: Attackers can execute arbitrary commands using the uploaded web shell.
  5. System compromise: Attackers gain control over the SAP system and data.

This critical vulnerability requires immediate attention and remediation.

Current Scope of Attacks Utilizing CVE-2025-31324

In late January 2025, suspicious HTTP requests targeting the /developmentserver/metadatauploader endpoint were observed. Following public disclosure, various attacks attempted to exploit this vulnerability to deploy JSP web shells.

Reconnaissance and Tool Deployment

Post-exploitation, attackers use reconnaissance commands to gather system information, such as:

  • cat /etc/hosts
  • ps -ef
  • netstat -tenp

Attackers primarily deploy web shells, including variants like ran.jsp and tools such as GOREVERSE for reverse shell capabilities.

Exploit Analysis

Onapsis has documented that exploitation began with reconnaissance from January 20, 2025, leading to successful web shell deployments by March 2025. The vulnerability's wide exposure is exacerbated by the inclusion of Visual Composer in default SAP installations.

Recommendations

Organizations are advised to:

  • Install the emergency patch from SAP.
  • Disable Visual Composer if not in use.
  • Monitor for suspicious activity and established web shells.

Indicators of Compromise

SAP recommends checking specific OS directories for indicators of compromise. The presence of files such as 'jsp', 'java', or 'class' in the following directories indicates potential exploitation:

  • C:\usr\sap<SID><InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\root
  • C:\usr\sap<SID><InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work
  • C:\usr\sap<SID><InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work\sync

Observed Tactics

The Onapsis Research Labs have mapped observed tactics to the MITRE ATT&CK Framework:

  • T1190 (Exploit Public-Facing Application)
  • T1505.003 (Server Software Component: Web Shell)

Conclusion

Organizations must act quickly to address CVE-2025-31324. GrackerAI, an AI-powered cybersecurity marketing platform, offers tools to help organizations transform security news into strategic content opportunities. By leveraging GrackerAI, marketing teams can stay ahead of emerging threats, monitor trends, and produce relevant content tailored for cybersecurity professionals.

Explore our services at GrackerAI or contact us for more information.

Hitesh Suthar
Hitesh Suthar

Software Developer

 

Platform developer crafting the seamless integrations that connect GrackerAI with Google Search Console and Bing Webmaster Tools. Builds the foundation that makes automated SEO portal creation possible.

Related Articles

2025 Nonprofit Marketing Trends: AI Strategies & Best Practices

Social media is a powerful tool for nonprofit organizations to connect with their target audiences. The evolving landscape of these platforms necessitates staying updated on best practices for optimal engagement and impact.

By Hitesh Kumawat July 23, 2025 5 min read
Read full article

Unlocking Business Potential: The Role of Chief Content Officers

Chief content officers (CCOs) are increasingly common in non-media companies, driven by the growing demand for unbranded content that resonates with consumers. Over 50 non-media companies, including Airbnb and HP, have appointed CCOs to foster authentic connections with their audiences. These roles differ significantly from traditional marketing positions, focusing on producing credible, independent content that builds trust. Angela Matusik from HP states, “This is not about steering people directly to purchase. It’s about creating long-term relationships with consumers.”

By Govind Kumar July 23, 2025 3 min read
Read full article

Revamping Corporate Sustainability: Beyond Checkboxes to Impact

Sustainability has become essential for businesses, transitioning from a secondary consideration to a core corporate strategy. Companies that view sustainability merely as a checkbox risk falling behind in today's market. A PwC survey indicates over 80 percent of consumers are concerned about climate change. As sustainability expectations shift, leaders are urged to build innovative ecosystems and enhance product offerings.

By Abhimanyu Singh July 22, 2025 3 min read
Read full article

AI Revolutionizes Content Creation in Digital Marketing & SaaS

The rise of artificial intelligence (AI) is transforming digital marketing strategies, making content creation more efficient. AI content writers provide innovative solutions for generating engaging and informative content at scale. These advancements in technology enable businesses to reach wider audiences with personalized messaging, which enhances engagement and conversion rates.

By Ankit Lohar July 22, 2025 3 min read
Read full article