By NHI Mgmt Group Editorial TeamBased on Pathlock: “Pathlock Research: CVE-2025-31324 Now Exploitable at Scale” (August 18, 2025)

TL;DR: SAP NetWeaver AS Java Visual Composer CVE-2025-31324 enables unauthenticated remote code execution through the metadata uploader endpoint, and public exploit code now makes abuse far easier for unpatched systems, according to Pathlock. Patch urgency is now inseparable from exposure reduction and post-compromise hunting because the blast radius can extend into adjacent identity-connected systems.


At a glance

What this is: This analysis covers SAP NetWeaver CVE-2025-31324, a pre-authentication remote code execution flaw in the Visual Composer metadata uploader that Pathlock says is now widely exploitable.

Why it matters: It matters because exploitable platform services can become identity and privilege entry points, especially where SAP service accounts, connected portals, and adjacent systems share trust.

By the numbers:

  • SAP CNA attributes CVSS 10.0 for CVE-2025-31324, while NVD attributes CVSS 9.8.

Context

SAP NetWeaver Visual Composer is a development component inside SAP NetWeaver AS Java that can expose administrative or upload-capable endpoints. When those endpoints accept attacker-controlled input before authentication, the issue is not only code execution but also the collapse of the trust boundary around a business platform that may already sit close to identity and access infrastructure.

Pathlock says CVE-2025-31324 is being actively exploited and that exploit tooling is now publicly available. In practice, that changes the defender's problem from a single patch event into an exposure-management and post-compromise-hunting problem across SAP Java services, connected portals, and any systems that trust the affected runtime.

For IAM and security teams, the important question is how much privilege, connectivity, and operational trust sits behind a component that was never intended to be internet-reachable. This is a pre-auth RCE issue, but the governance impact is broader because compromise can quickly spill into adjacent identity-connected systems.


Key questions

Q: What breaks when a pre-auth SAP upload endpoint is exposed to the internet?

A: A pre-auth upload endpoint turns an application service into an execution surface. If the endpoint accepts attacker-controlled content before authorization, patching alone is not enough because the exposure itself becomes the attack path. Teams need to assume that any reachable upload or metadata handler can become a compromise entry point if it was never meant to be public.

Q: Why does public exploit code make CVE-2025-31324 more dangerous?

A: Public exploit code reduces attacker skill requirements and shortens the time between disclosure and real abuse. Once tooling is easy to run, defenders face opportunistic scanning, faster weaponisation, and broader targeting. That increases the urgency of exposure reduction and post-patch verification, not just ticket closure.

Q: What are the signs that SAP NetWeaver Visual Composer exploitation is already underway?

A: Common signs include unexpected JSP files in the Visual Composer directories, suspicious shell history showing curl, wget, or piped bash execution, and signs of second-stage payloads. If attackers use tunneling services or deploy webshells such as helper.jsp or cache.jsp, that often indicates active post-exploitation activity rather than a failed scan or harmless probe.

Q: What should teams do if SAP NetWeaver compromise is suspected?

A: Isolate the affected nodes, preserve logs and file hashes, rotate service credentials and SSO, and rebuild the environment from a known-good baseline before reconnecting it. The priority is to contain any privileged runtime foothold and verify that no web shell or persistence mechanism remains on the host.


Technical breakdown

How pre-auth remote code execution works in Visual Composer

The flaw Pathlock describes sits in the Visual Composer metadata uploader endpoint, where missing authorization allows unauthenticated POST requests to reach server-side processing logic. Once attacker-controlled content is accepted, the application can be driven into remote code execution without a valid session. The risk is amplified when the upload surface is reachable from outside the network and when the backend runtime runs with privileges that exceed the application's intended role. In SAP environments, that often means the exploit path is not just a web issue but an application-to-platform compromise.

Practical implication: Restrict or block the metadata uploader path at the edge and treat internet reachability as a control failure, not a convenience setting.

Why public exploit code changes the operational risk

Public proof-of-concept code lowers attacker skill requirements and compresses the time between disclosure and exploitation. Pathlock notes that the exploit is simple to run and that AI tools further reduce the barrier for non-specialists. That shifts the defender's burden from assuming only advanced actors can abuse the flaw to assuming opportunistic scanning, rapid weaponisation, and mass targeting. In practical terms, patch status alone is not enough if the endpoint remains exposed or if attacker activity has already moved into persistence and post-exploitation tooling.

Practical implication: Treat public exploit availability as a trigger for immediate exposure reduction, not just accelerated patch planning.

How SAP service account privilege expands the blast radius

Successful exploitation commonly lands in the context of the SAP Java service account, which can carry broad access into portals, identity-connected applications, and shared infrastructure. That is why pre-auth RCE in an application tier often becomes a credential and lateral-movement problem after initial execution. Once the attacker can write files, spawn shells, or invoke adjacent services, the compromise stops being local to the vulnerable endpoint. The technical question for defenders is not only what executed, but what that runtime was trusted to reach next.

Practical implication: Map the SAP Java service account's downstream access paths so you can limit lateral movement if the runtime is compromised.


Threat narrative

Attacker objective: The attacker aims to gain code execution on SAP NetWeaver systems and then use that foothold to persist, move laterally, and access connected enterprise systems.

  1. Entry occurs through unauthenticated requests to the Visual Composer metadata uploader endpoint, which accepts attacker-controlled content before authorization.
  2. Escalation follows when the accepted payload yields remote code execution in the SAP NetWeaver Java runtime, often under the SAP service account context.
  3. Impact expands as attackers drop web shells, persist on the host, and pivot into portals, identity services, or connected systems that trust the SAP runtime.
  • Gladinet Hard-Coded Keys RCE Exploitation: Actively exploited hard-coded keys in Gladinet CentreStack and Triofox enable remote code execution.
  • Uber breach 2016: An AWS key posted to Uber's private GitHub repositories let intruders copy data on 57 million people; Uber paid $100,000 and hid it for a year.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Pre-auth RCE in a business platform becomes an identity problem once execution lands under a privileged service account: The technical flaw is not just unauthorised code execution, it is execution in a runtime that already carries trust into other enterprise systems. When SAP Java services sit near portals, identity-connected applications, or shared infrastructure, the compromise boundary expands beyond the vulnerable endpoint. Practitioners should treat platform reachability as a governance issue, not just an application patch issue.

Public exploit availability collapses the usual assumption that exposure and exploitation are separable in time: Security programmes often assume there is a meaningful interval between patch release and real abuse. Pathlock's account of leaked proof-of-concept code and openly available tooling shows that window can be very short. That means exposure reduction, patch validation, and hunting must operate as one response motion rather than three separate queues.

Identity blast radius is the right named concept for this class of SAP compromise: Once attackers execute inside the SAP Java runtime, the question becomes which downstream systems inherit the service account's trust. That is the real control boundary failure, because service account privilege is often broader than the application surface suggests. The practitioner conclusion is to govern the blast radius, not just the vulnerable binary.

Least privilege is defined too late when the platform's runtime already has more trust than the business service needs: CVE-2025-31324 shows how pre-auth compromise exposes a structural mismatch between application reachability and runtime privilege. The problem is not simply missing access controls on one endpoint. It is that the underlying execution context can already touch systems that the application never needed to reach directly.

Post-compromise hunting is part of vulnerability governance, not an optional incident add-on: Pathlock's guidance to check logs, new files, process telemetry, and suspicious outbound connections reflects a larger truth about internet-reachable enterprise platforms. If a flaw can plausibly be exploited before remediation is complete, then verification and hunting become part of the control itself. Practitioners should view remediation as incomplete until compromise evidence has been ruled out.

From our research library:

What this signals

Identity blast radius: Pre-auth application compromise matters most when the runtime already sits inside a wider trust chain. For SAP teams, the practical issue is not only whether the vulnerable endpoint is patched, but whether the service account and adjacent integrations can be reached if that endpoint is abused.

Pathlock's account shows why patch governance and exposure governance have to be coordinated. When exploit code is public, teams cannot rely on maintenance windows or normal remediation cadence alone, and the safest response is to reduce reachability while hunting for evidence of compromise.

Internal repositories are 6x more likely to contain secrets than public ones (32.2% vs 5.6%), according to the State of Secrets Sprawl 2026. That pattern reinforces the same governance lesson here: once attacker tooling and internal trust assumptions intersect, latent exposure becomes an operational incident, not just a code issue.


For practitioners

  • Restrict the metadata uploader endpoint Block or tightly allow-list /developmentserver/metadatauploader at SAP Web Dispatcher, ICM, or WAF, and remove internet exposure from any developer or administrative path.
  • Apply both SAP notes Validate SAP Security Note 3594142 and the related corrective Note 3604119 on every Java instance and cluster node, then restart affected services where required.
  • Hunt for uploader abuse Search HTTP and ICM logs for POST requests to /developmentserver/metadatauploader with application/octet-stream or multipart bodies, and review unexpected 200 responses.
  • Check for IRJ persistence Inspect IRJ servlet paths for unexpected .jsp and .class files, unusual timestamps, and SAPJVM-spawned shells or compression utilities.
  • Treat compromise as a rebuild event If exploitation is suspected, isolate the affected node, preserve ICM, Web Dispatcher, and defaultTrace logs, rotate service credentials and SSO, and rebuild from a known-good baseline before reconnecting.

Key takeaways

  • CVE-2025-31324 is dangerous because it combines unauthenticated execution with a business platform runtime that can reach beyond the vulnerable endpoint.
  • Public exploit availability means defenders need to assume active abuse, not just theoretical risk, when exposure remains in place.
  • The limiting control is not only patching. It is reducing external reachability, validating downstream privilege, and hunting for post-compromise evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe flaw permits unauthenticated execution through a reachable upload endpoint.
NHI-05 — Overprivileged NHIExploitation lands in a privileged SAP service account context with broad downstream trust.
NHI-06 — Insecure Cloud Deployment ConfigurationsThe risk is amplified when administrative or developer paths remain externally reachable.
Recommendation — Audit externally reachable SAP endpoints and remove any unauthenticated upload path from production exposure. Map SAP service account privileges to downstream systems and trim any access the runtime does not need. Segment and restrict management and development endpoints so they cannot be reached from the internet.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article describes post-exploitation pivoting from SAP runtime compromise into adjacent systems.
Recommendation — Correlate suspicious SAP execution with credential and lateral-movement telemetry to catch follow-on abuse.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsDownstream access rights determine how far a compromised SAP runtime can move.
Recommendation — Review SAP service entitlements and remove any authorization that expands the blast radius of exploitation.

Key terms

  • Pre-auth RCE: Remote code execution that occurs before a system has authenticated the requester. This is especially dangerous because the attacker does not need valid credentials, so the vulnerability can often be triggered from the public internet with a single request if the endpoint is reachable.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Metadata uploader: A server-side upload endpoint that accepts content for later processing by an application. When it lacks authorization checks, it can become an execution path for attacker-controlled files or data, especially if the backend runtime trusts the uploaded material.
  • Post-compromise hunting: Post-compromise hunting is the retrospective search for evidence that an attacker already used a vulnerability, even if the initial alert is absent. It combines log review, host telemetry, file inspection, and process analysis to determine whether the incident moved beyond exposure into active exploitation.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org