Join our Newsletter — 33% off our NHI Course

SAP NetWeaver CVE-2025-31324: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: SAP NetWeaver AS Java Visual Composer CVE-2025-31324 enables unauthenticated remote code execution through the metadata uploader endpoint, and public exploit code now makes abuse far easier for unpatched systems, according to Pathlock. Patch urgency is now inseparable from exposure reduction and post-compromise hunting because the blast radius can extend into adjacent identity-connected systems.

Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “Pathlock Research: CVE-2025-31324 Now Exploitable at Scale”.

By the numbers:

  • SAP CNA attributes CVSS 10.0 for CVE-2025-31324, while NVD attributes CVSS 9.8.

Key questions

Q: What breaks when a pre-auth SAP upload endpoint is exposed to the internet?

A: A pre-auth upload endpoint turns an application service into an execution surface.

Q: Why does public exploit code make CVE-2025-31324 more dangerous?

A: Public exploit code reduces attacker skill requirements and shortens the time between disclosure and real abuse.

Q: What are the signs that SAP NetWeaver Visual Composer exploitation is already underway?

A: Common signs include unexpected JSP files in the Visual Composer directories, suspicious shell history showing curl, wget, or piped bash execution, and signs of second-stage payloads.

Practitioner guidance

  • Restrict the metadata uploader endpoint Block or tightly allow-list /developmentserver/metadatauploader at SAP Web Dispatcher, ICM, or WAF, and remove internet exposure from any developer or administrative path.
  • Apply both SAP notes Validate SAP Security Note 3594142 and the related corrective Note 3604119 on every Java instance and cluster node, then restart affected services where required.
  • Hunt for uploader abuse Search HTTP and ICM logs for POST requests to /developmentserver/metadatauploader with application/octet-stream or multipart bodies, and review unexpected 200 responses.

Bottom line: CVE-2025-31324 is dangerous because it combines unauthenticated execution with a business platform runtime that can reach beyond the vulnerable endpoint.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 19 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Pre-auth RCE in a business platform becomes an identity problem once execution lands under a privileged service account: The technical flaw is not just unauthorised code execution, it is execution in a runtime that already carries trust into other enterprise systems. When SAP Java services sit near portals, identity-connected applications, or shared infrastructure, the compromise boundary expands beyond the vulnerable endpoint. Practitioners should treat platform reachability as a governance issue, not just an application patch issue.

A few things that frame the scale:

  • Internal repositories are 6x more likely to contain secrets than public ones (32.2% vs 5.6%), contradicting the assumption that private repos are safe, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: What should teams do if SAP NetWeaver compromise is suspected?

A: Isolate the affected nodes, preserve logs and file hashes, rotate service credentials and SSO, and rebuild the environment from a known-good baseline before reconnecting it. The priority is to contain any privileged runtime foothold and verify that no web shell or persistence mechanism remains on the host.

👉 Read our full editorial: SAP NetWeaver CVE-2025-31324 exposes the danger of pre-auth RCE


This post was modified 19 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.