- Beanlian, ransomexx and others jump netweaver -tape carriage
- At the end of April, SAP got a 10/10 Error in Netweaver Visual Composer Metadata Uploader
- Scientists claim there are 1,200 vulnerable cases
Several ransomware operators are trying to take advantage of the newly discovered, maximum difficulty error affecting SAP Netweaver Visual Composer. This is, among other things, reliable a cyber security company that also reported the original error.
At the end of April, security researchers reported that more than 1,200 SAP occurrences were in danger of being hijacked due to a maximum severity found in Netweaver Visual Composers Metadata Uploader component.
The error stems from the fact that the uploader was not protected with proper permission, enabling unauthorized actors to upload malicious executable substances.
More critical shortcomings
The error is traced as CVE-2025-31324, and despite SAP releasing a patch pretty fast, several wild attacks were discovered.
Now Reliaquest said that the evidence that suggested involving Bianlian and Ransomexx, two known ransomware families. Other researchers also claim that Chinese state -sponsored actors also participated in the action. “We assess with moderate confidence that Bianlian was involved in at least one incident,” Reliaquest said. “In a separate incident, we observed the implementation of” Pipemagic “, a modular back door attached to Ransomexx.”
The researchers also said that Miscreants moved quickly when malware was deployed “only hours after global exploitation”.
Earlier this week, SAP patched a separate, also critical, zero-day vulnerability in the Netweaver server. This one, said it was tied in attacks targeting some of the world’s largest companies. It is traced as CVE-2025-42999 and has a severity of 9.1/10 (critical). The error also discovered in Netweaver Visual Composer Metadata uploads if a privileged user can upload non -be -proclaimed or malicious content, such as “when deserialized, can potentially lead to a compromise of confidentiality, integrity and accessibility of the host system.”
SAP said it found this error when analyzing the maximum difficulty. Both were allegedly abused in attacks since January 2025.
Via Bleeping computer