SAP NetWeaver 0-Day Vulnerability Exploited in the Wild to Deploy Webshells

SAP released an emergency out-of-band patch addressing CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver Visual Composer with the highest possible CVSS score of 10.0.  This vulnerability stems from a missing authorization check in the Metadata Uploader component, allowing unauthenticated attackers to upload malicious executable files by sending specially crafted POST requests to the /developmentserver/metadatauploader […]

The post SAP NetWeaver 0-Day Vulnerability Exploited in the Wild to Deploy Webshells appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: