216.73.217.98

New Critical Vulnerability Uncovered in SAP NetWeaver

· Published 28/04/2025 16:27 · Modified 28/04/2025 18:50

Export JSON

Essential information

Published
28/04/2025 16:27
Modified
28/04/2025 18:50
Tags
2025-04-28 CVE-2025-31324 brute ratel file upload heaven's gate sap netweaver webshell
Related entities
2 observables, 1 malware, 2 others

Description

A critical vulnerability in Visual Composer, identified as with a severity score of 10, allows unauthorized file uploads and execution of malicious files. Initially suspected as a remote file inclusion issue, it was confirmed to be an unrestricted vulnerability. Attackers exploited this vulnerability to upload JSP webshells, gaining remote control and executing arbitrary commands. The exploitation involved abusing the /developmentserver/metadatauploader endpoint. Attackers used sophisticated tools like and the Heaven's Gate technique for command-and-control and evasion. SAP released a patch to address this vulnerability, which is strongly recommended to be applied immediately.

External references