216.73.216.197

CVE-2025-31324: Critical SAP Vulnerability & How to Protect Your Enterprise

· Published 10/09/2025 19:32 · Modified 10/09/2025 20:15

Export JSON

Essential information

Published
10/09/2025 19:32
Modified
10/09/2025 20:15
Tags
2025-09-10 CVE-2025-31324 auto-color exploit metadatauploader netweaver remote code execution sap vulnerability
Related entities
4 observables, 1 intrusion sets (apt), 4 techniques (mitre), 3 others

Description

A critical () affects Development Server, allowing attackers to upload malicious files through the endpoint. This enables unauthenticated , potentially leading to enterprise network compromise, data theft, and disruption of critical processes. Active exploitation began in March 2025, with widespread attacks following the public release of an script in August 2025. The stems from improper validation of uploaded model files, allowing attackers to execute arbitrary code within the server context. Protective measures include immediate patching, network monitoring, and restricting development server exposure to trusted networks.

External references