CISA Issues Alert on Active Exploitation of SAP Zero-Day Vulnerability

CISA Issues Alert on Active Exploitation of SAP Zero-Day Vulnerability

CISA Flags Actively Exploited SAP NetWeaver Vulnerability in KEV List

On April 29, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified a high-risk vulnerability in SAP NetWeaver and officially included it in its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2025-31324: A Severe Zero-Day in SAP Visual Composer

Designated as CVE-2025-31324, the vulnerability has earned a perfect CVSS score of 10.0 and has been under active exploitation since at least March 2025. This zero-day affects the SAP NetWeaver Application Server for Java (AS Java), targeting the Visual Composer’s Metadata Uploader module.

The flaw stems from an unprotected file upload mechanism that enables attackers to place executable payloads on exposed systems without requiring credentials. According to the CWE-434 classification, this issue relates to the unrestricted upload of dangerous file types.

Onapsis researchers, leveraging their global threat monitoring infrastructure, confirmed ongoing exploitation. “The exposed development environment allows attackers to upload malicious code freely—no authentication is needed to breach the system,” they reported.

Although Visual Composer isn’t a default component, experts believe it’s enabled in the majority of SAP Java environments—estimated between 50% and 70%—due to its widespread use by enterprise developers who prefer no-code/low-code application building.

Risk Overview

CategoryInformation
Impacted SystemsSAP NetWeaver AS Java (Visual Composer module, version VCFRAMEWORK 7.50). The exposed endpoint at developmentserver/metadatauploader is directly vulnerable.
Potential ConsequencesAllows attackers to upload malicious files, enabling full system takeover through remote code execution (RCE).
Attack ConditionsNo login or elevated permissions needed. An attacker with basic network access can reach the vulnerable endpoint.
Severity RatingCVSS v3.1: 10.0 (Maximum/Critical)

Exploitation Timeline and Risk Context of SAP Zero-Day CVE-2025-31324

ReliaQuest was the first to publicly disclose signs of in-the-wild exploitation on April 22, 2025. Forensic evidence points to malicious activity beginning as early as March. Attackers have specifically targeted the vulnerable /developmentserver/metadatauploader endpoint to deploy JSP-based webshells—providing persistent backdoor access to affected SAP systems.

The attack path requires no authentication and enables full system compromise, giving adversaries the ability to extract sensitive enterprise data, including financial records and personal information. Onapsis threat researchers warn that such exploitation results in “immediate full compromise,” and may also be leveraged to move laterally into other parts of an organization’s network.

In response to the growing threat, CISA added CVE-2025-31324 to its Known Exploited Vulnerabilities (KEV) catalog. Under Binding Operational Directive (BOD) 22-01, all U.S. federal agencies must apply remediation measures by May 20, 2025.

SAP responded by issuing an emergency fix on April 24, 2025, via Security Note #3594142. For organizations unable to patch immediately, SAP has outlined interim mitigations in Note #3593336.

Additionally, SAP released an FAQ to help customers detect potential breaches. Indicators of compromise include the presence of unexpected .jsp, .java, or .class files in Visual Composer directories.

Experts emphasize that this vulnerability poses a particularly high risk for enterprises still relying on on-premises SAP NetWeaver deployments, which often lack the layered defenses common in cloud-native environments.

More Articles & Posts