SAP disclosed CVE-2025-31324, a critical CVSS 10.0 zero-day in NetWeaver Visual Composer caused by a missing authorization check in the Metadata Uploader component. The flaw allows unauthenticated attackers to send crafted POST requests to the /developmentserver/metadatauploader endpoint and upload malicious files, creating a path to remote code execution on affected SAP NetWeaver 7.xx systems where Visual Composer is installed. Rapid7 reported that exploitation had been occurring in the wild since at least late March, with multiple customer environments affected and manufacturing organizations appearing heavily targeted.
Investigators observed attackers deploying JSP webshells such as helper.jsp, cache.jsp, and randomly named eight-character files in NetWeaver directories tied to irj, indicating post-exploitation persistence and hands-on access. As defenders rushed to respond, public GitHub repositories quickly appeared with proof-of-concept code, Burp and Nuclei detection templates, and later compromise-assessment tooling from Onapsis and Mandiant covering CVE-2025-31324 and the related CVE-2025-42999. SAP urged customers to patch immediately or disable Visual Composer, restrict access to the vulnerable endpoint, and investigate systems for indicators of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A GitHub-hosted assessment tool for CVE-2025-31324 and CVE-2025-42999 was published by Onapsis and Mandiant to help organizations evaluate vulnerability exposure and signs of compromise.
Rapid7 published research on 2025-04-28 confirming in-the-wild exploitation across multiple customer environments and describing attacker use of JSP webshells such as helper.jsp and cache.jsp. The company also released detection and exposure assessment coverage, while noting it had not attributed the activity to a specific threat actor.
A proof-of-concept repository for CVE-2025-31324 was published on GitHub, demonstrating public technical exploitation details for the unauthenticated upload issue in SAP NetWeaver Visual Composer.
Public defensive tooling to identify exposure to CVE-2025-31324 began appearing on GitHub, including a Burp Suite extension and later a Nuclei template for checking vulnerable SAP NetWeaver instances.
On 2025-04-24, SAP disclosed CVE-2025-31324, a critical 10.0-severity missing authorization flaw in the NetWeaver Visual Composer Metadata Uploader that allows unauthenticated file upload. SAP advised customers to patch immediately or disable Visual Composer, restrict access to the vulnerable endpoint, and investigate for compromise.
Rapid7 observed active exploitation of CVE-2025-31324 dating back to at least 2025-03-27. The attacks targeted SAP NetWeaver Visual Composer systems and involved uploading JSP webshells, with manufacturing organizations notably affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcerapid7.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.