THREAT LEVEL - HIGH

29-04-2025

New Critical SAP NetWeaver Vulnerability

Threat Level Description

IthacaLabs has maintained the Threat Level (High) adding a new observation:

An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

We have observed that a that a critical vulnerability affecting SAP NetWeaver Application Server has been identified and is being actively exploited in the wild.

A remote unauthenticated attacker, by exploiting this issue, could upload arbitrary files, execute malicious code with elevated privileges, and obtain full control over SAP resources, including the SAP system database.

This vulnerability, tracked as CVE-2025-31324, is an unrestricted file upload flaw.

Threat actors have been observed uploading JSP-based web shells into the system (servlet_jsp/irj/root/), allowing persistent access and facilitating the deployment of additional malicious frameworks.

Post-exploitation techniques include bypassing endpoint security protections and executing commands with system-level privileges.

The exploitation activity indicates a concerning pattern, suggesting that adversaries may act as Initial Access Brokers, offering access to compromised SAP systems to other threat groups on underground forums.

Affected Products:

  • SAP NetWeaver Application Server Java systems exposing the /developmentserver/metadatauploader endpoint.

Recommendation(s):

You should proceed immediately and apply the relevant security patches provided by the vendor.

In addition, the following actions are recommended:

  • Review and restrict access to the /developmentserver/metadatauploader endpoint.
  • Monitor systems for the presence of unauthorized JSP web shells.
  • Search for known indicators of compromise (IOCs) in the following paths:
    • C:usrsap<SID><InstanceID>j2eeclusterappssap.comirjservlet_jspirjroot
    • C:usrsap<SID><InstanceID>j2eeclusterappssap.comirjservlet_jspirjwork
    • C:usrsap<SID><InstanceID>j2eeclusterappssap.comirjservlet_jspirjworksync

ProjectDiscovery has released two nuclei templates to detect CVE-2025-31324 so as to verify if users are vulnerable or not and also determine if their instances are compromised by the JSP web shell backdoor used by threat actors:

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes

SIGN UP

Get the latest Threat Alerts in your inbox.