CVE-2025-31324 Exploited in the Wild: What We’ve Found in the Aftermath
Key Takeaways
SAP disclosed a critical vulnerability (CVE-2025-31324) in NetWeaver’s Visual Composer that allows unauthenticated file uploads, leading to potential remote code execution, with a CVSS score of 10.0.
Real-world exploitation has been confirmed in multiple customer environments, where attackers were able to deploy malicious webshells for persistent access to compromised systems.
Immediate actions for SAP customers include applying the necessary security patch, removing unauthorized JSP files, and reviewing logs for suspicious activity to mitigate the risks associated with this vulnerability.
In April 2025, SAP revealed a critical vulnerability (CVE-2025-31324) in NetWeaver’s Visual Composer that allows unauthenticated file uploads leading to remote code execution, which has been actively exploited in multiple customer environments, necessitating urgent mitigation actions.
