CVE-2025-31324 – Critical Remote Code Execution Vulnerability in SAP NetWeaver Visual Composer

ISGroup Cybersecurity

CVE‑2025‑31324 is a critical zero-day vulnerability (CVSS 10.0) in the Visual Composer (VCFRAMEWORK) component of SAP NetWeaver, disclosed on April 22, 2025. SAP released an emergency patch on April 24, 2025. SAP NetWeaver Visual Composer is often enabled in NetWeaver Java systems—even if not installed by default—because it allows business analysts to create applications without writing code. The vulnerability has been observed under active exploitation since mid-March 2025: attackers have deployed JSP webshells (e.g., helper.jsp, cache.jsp) to maintain persistence and execute commands with the privileges of the system SAP process.

ProductSAP NetWeaver
Date2025-07-31 10:30:37
Information
  • Fix Available
  • Active Exploitation

Technical Summary

The flaw stems from a missing authorization check in the /developmentserver/metadatauploader endpoint of Visual Composer, which allows unauthenticated attackers to upload arbitrary files to the server—leading to Remote Code Execution (RCE) with SAP application privileges. After exploitation, attackers typically deposit malicious JSP webshells in directories such as /j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root/, gaining remote access and full control of the system (on both Linux and Windows environments). The impact includes the complete compromise of the SAP environment: attackers can execute system commands, access databases, alter financial data or PII, deploy ransomware, perform lateral movement within the network, and evade defenses. All versions of SAP NetWeaver Java 7.1x and higher are vulnerable if Visual Composer is present or enabled.

Recommendations

  • Immediately apply SAP Security Note 3594142: it provides emergency patches to fix the missing authorization check in Visual Composer.
  • Also apply SAP Security Note 3604119, which addresses an additional insecure deserialization vulnerability, eliminating residual risks left by the first patch—even if Note 3594142 has already been implemented.
  • If patching is not possible, implement the “Option 0” mitigation: completely remove the sap.com/devserver_metadataupload_ear application as recommended by SAP. Previous workarounds, options 1 and 2, are deprecated.
  • Perform a compromise assessment using scanners or available tools to identify Indicators of Compromise (IoCs)—look for unusual .jsp, .java, and .class files in relevant directories and known webshell names such as helper.jsp or cache.jsp.
  • Check HTTP access logs targeting the /developmentserver/metadatauploader endpoint to identify exploitation attempts. Use pattern-based recognition or file names to detect webshell activity.
  • For network defense, implement protections such as firewall rules or signature-based detection to block exploitation attempts, and use asset discovery tools to identify exposed SAP NetWeaver endpoints.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert